Module 4 of 6
DMARC — Policy, Alignment, and Enforcement
DMARC (Domain-based Message Authentication, Reporting & Conformance) is the piece that finally closes the gap both SPF and DKIM leave open on their own: it requires that a passing SPF or DKIM result actually aligns with the visible header From: domain – the one a person reads.
Alignment: relaxed vs. strict
- Relaxed alignment (the default): the authenticated domain and the header
From:domain just need to share the same organizational domain –mail.example.comaligns withexample.com. - Strict alignment: they must match exactly, subdomain and all.
A message needs SPF or DKIM to both pass and align with the header From: domain to pass DMARC overall.
A real record
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com
p=– the policy:none(monitor only),quarantine(send failing mail to spam), orreject(block it outright).pct=– what percentage of failing mail the policy applies to (useful for a gradual rollout).rua=– where aggregate reports get sent (Module 5 covers what's actually in them).
Why p=none is not protection
This is the single most common DMARC misconception: publishing a DMARC record with p=none does not stop a single spoofed message. It only turns on reporting – you start seeing what's failing and from where, but nothing gets blocked or quarantined until the policy actually moves to quarantine or reject. A domain sitting at p=none indefinitely has all the visibility of DMARC and none of the protection – which is exactly why "monitor, then tighten" has to be a deliberate rollout plan, not a permanent resting state. Course 2 covers building that rollout safely.
Check your own domain's current policy with ActiScan's DMARC checker – and if it's sitting at p=none, that's worth a real plan, not just a passing grade.
Try it yourself: DMARC Record Checker