diagnostic · sourced answer

Why DMARC Says Quarantine or Reject Policy Not Enabled

A DMARC policy is not enabled when your DNS record contains p=none, which tells receiving servers to take no action against emails that fail authentication. To enable a restrictive policy, you must change the p tag to either p=quarantine or p=reject in your TXT record. This transition moves your domain from monitoring mode to active enforcement of SPF and DKIM alignment.

Understanding the p=none Policy

The p=none tag is used for monitoring. It allows you to collect RUA and RUF reports to see who is sending mail on your behalf without risking legitimate mail being blocked. While this is a necessary first step for auditing, it provides no security benefit against spoofing because the receiving mail server is instructed to deliver the message regardless of authentication failure.

Quarantine vs Reject Policies

The p=quarantine policy instructs the receiver to treat unauthenticated mail as suspicious, typically moving it to the spam or junk folder. The p=reject policy is the strictest setting, instructing the receiver to bounce the email entirely. Both of these settings are considered enabled policies because they actively mitigate the risk of domain impersonation by applying a penalty to failing messages.

How to Update Your Policy

To enable enforcement, access your DNS provider and locate the TXT record for _dmarc.yourdomain.com. Change the value from v=DMARC1; p=none; to v=DMARC1; p=quarantine; or v=DMARC1; p=reject;. Ensure that your SPF and DKIM records are correctly configured before making this change to avoid blocking your own legitimate traffic. You can use SendHQ free tools (https://sendhq.cc/tools) to verify your syntax before deploying.

The Role of Alignment

DMARC enforcement depends on alignment. For a message to pass DMARC, it must pass SPF or DKIM, and the domain in the From header must match the domain used in the SPF or DKIM check. If you enable p=reject without proper alignment, any third party service sending mail on your behalf will be blocked unless they are authorized in your SPF record and sign with a valid DKIM key.

Questions teams ask

Is p=none a valid DMARC record?

Yes, it is syntactically valid and used for monitoring, but it does not provide active protection against spoofing.

Will p=reject stop my emails from being delivered?

Only if your emails fail SPF or DKIM alignment. If your authentication is correct, p=reject will not affect your legitimate mail.

Can I use p=quarantine and p=reject together?

No, the p tag accepts only one value. However, you can use sp= to set a different policy for subdomains.

Primary sources