diagnostic · sourced answer
Why DMARC Says Quarantine or Reject Policy Not Enabled
A DMARC policy is not enabled when your DNS record contains p=none, which tells receiving servers to take no action against emails that fail authentication. To enable a restrictive policy, you must change the p tag to either p=quarantine or p=reject in your TXT record. This transition moves your domain from monitoring mode to active enforcement of SPF and DKIM alignment.
Understanding the p=none Policy
The p=none tag is used for monitoring. It allows you to collect RUA and RUF reports to see who is sending mail on your behalf without risking legitimate mail being blocked. While this is a necessary first step for auditing, it provides no security benefit against spoofing because the receiving mail server is instructed to deliver the message regardless of authentication failure.
Quarantine vs Reject Policies
The p=quarantine policy instructs the receiver to treat unauthenticated mail as suspicious, typically moving it to the spam or junk folder. The p=reject policy is the strictest setting, instructing the receiver to bounce the email entirely. Both of these settings are considered enabled policies because they actively mitigate the risk of domain impersonation by applying a penalty to failing messages.
How to Update Your Policy
To enable enforcement, access your DNS provider and locate the TXT record for _dmarc.yourdomain.com. Change the value from v=DMARC1; p=none; to v=DMARC1; p=quarantine; or v=DMARC1; p=reject;. Ensure that your SPF and DKIM records are correctly configured before making this change to avoid blocking your own legitimate traffic. You can use SendHQ free tools (https://sendhq.cc/tools) to verify your syntax before deploying.
The Role of Alignment
DMARC enforcement depends on alignment. For a message to pass DMARC, it must pass SPF or DKIM, and the domain in the From header must match the domain used in the SPF or DKIM check. If you enable p=reject without proper alignment, any third party service sending mail on your behalf will be blocked unless they are authorized in your SPF record and sign with a valid DKIM key.
Questions teams ask
Is p=none a valid DMARC record?
Yes, it is syntactically valid and used for monitoring, but it does not provide active protection against spoofing.
Will p=reject stop my emails from being delivered?
Only if your emails fail SPF or DKIM alignment. If your authentication is correct, p=reject will not affect your legitimate mail.
Can I use p=quarantine and p=reject together?
No, the p tag accepts only one value. However, you can use sp= to set a different policy for subdomains.
Primary sources
- RFC 7489: Domain-based Message Authentication, Reporting and Conformance — RFC Editor
- RFC 7208: Sender Policy Framework — RFC Editor
- RFC 6376: DomainKeys Identified Mail — RFC Editor