technical · sourced answer

DMARC Record: Definition and Implementation Guide

A DMARC record is a DNS TXT record that tells receiving mail servers how to handle emails that fail SPF or DKIM authentication. It allows domain owners to specify a policy of none, quarantine, or reject for unauthenticated mail, ensuring that only authorized senders can use the domain.

Mechanical Operation

DMARC operates by checking for alignment between the domain in the From header and the domains validated by SPF and DKIM. If the SPF check passes and the domain matches, or if the DKIM signature is valid and the domain matches, the email is DMARC compliant. If both fail or are misaligned, the receiver applies the policy defined in the DMARC record to determine if the message should be delivered, flagged, or blocked.

Importance for Senders

DMARC prevents domain spoofing and phishing by giving the sender control over how receivers treat unauthorized mail. Without a DMARC record, receivers have no explicit instruction on what to do with failed authentication, which can lead to inconsistent delivery. Implementing a strict policy reduces the risk of attackers sending fraudulent emails that appear to come from your official corporate domain.

Operational Notes and Mistakes

A common mistake is moving to a reject policy before analyzing reporting data. Senders should start with p=none to monitor traffic without affecting delivery. Another frequent error is incorrect syntax in the TXT record, such as missing semicolons or invalid tags. Using SendHQ or its free tools (https://sendhq.cc/tools) can help verify that the record is formatted correctly before deployment.

Concrete Example

A typical DMARC record looks like v=DMARC1; p=quarantine; rua=mailto:reports@example.com. In this example, v=DMARC1 identifies the record version, p=quarantine instructs the receiver to send failed emails to the spam folder, and rua specifies the email address where aggregate XML reports should be sent for analysis.

Policy Levels

There are three primary policy levels. p=none is monitoring mode, where no action is taken against failed mail. p=quarantine sends failed mail to the recipient's junk folder. p=reject is the strictest level, instructing the receiving server to bounce the email entirely, preventing it from ever reaching the recipient's mailbox.

Questions teams ask

Does DMARC replace SPF or DKIM?

No, DMARC builds upon SPF and DKIM. It requires at least one of them to be present and valid to verify the sender identity and provides the policy for when they fail.

What is the difference between rua and ruf?

rua is used for aggregate reports that provide high level statistics on mail volume and authentication. ruf is used for forensic reports that provide detailed information about individual failed messages.

Can I have multiple DMARC records?

No, a domain must have only one DMARC record. If multiple records are found in the DNS, receiving servers will typically ignore all of them, leaving the domain unprotected.

Primary sources