Domain policy (p=)
— what to do with mail that fails DMARCSubdomain policy (sp=)
— optional; inherits p= if not setEnforcement percentage (pct=)
1% — roll out gradually100% — fully enforced
Policy applies to 100% of failing messages. Fully enforced.
Reporting addresses
Aggregate reports (rua=)
RecommendedXML summary reports sent daily. Set this to see who is sending mail as your domain.
Strongly recommended. Without rua= you have zero visibility into authentication failures.
mailto:Forensic reports (ruf=) — optional
Per-message failure reports. Less commonly supported; leave blank if not needed.
mailto:Alignment modes
— how strictly From: domain must match SPF/DKIMDKIM alignment (adkim=)
SPF alignment (aspf=)
Failure reporting options (fo=)
— when to generate forensic reportsGenerated DMARC record
_dmarc.yourdomain.com TXT
v=DMARC1; p=none
How to publish this record
- 1Log in to your DNS provider for the domain you want to protect.
- 2Create a new TXT record:
Host / Name:_dmarc(do not use your bare domain or @)Type:TXTTTL:3600Value:v=DMARC1; p=none - 3Wait 5–60 minutes for DNS propagation, then verify with our SPF / DKIM / DMARC Checker or DMARC Analyzer.
- 4Start with
p=noneand monitor your rua= reports for 2–4 weeks. Once you confirm all legitimate senders pass, move top=quarantine, thenp=reject.
DMARC configured — now enforce it without the risk
Mailflo monitors your DMARC reports, tracks who is failing authentication, and alerts you before you move enforcement levels — so you never accidentally block legitimate mail.
See Mailflo plans