Guides

DMARC, explained by people who read the reports.

Step-by-step guides for getting a domain from no protection to full enforcement — without breaking legitimate mail.

Where to start

Every domain takes the same route, and the order matters more than the pace. Publish a monitoring-only record so reports start arriving, spend a few weeks finding out who really sends mail as you, authorise or fix each of those senders, and only then turn the policy up. Going straight to p=reject before the reports have shown you the full list is how legitimate mail gets thrown away — and it is rarely the mail anyone notices missing on the first day. Invoice reminders, password resets and the output of a forgotten cron job all send without anyone testing them.

Three of the guides below cover that route end to end. Publish your first DMARC record is the five-minute DNS change that starts the report flow and changes nothing about how your mail is treated. How to read a DMARC aggregate report turns the XML that follows into a short list of senders worth chasing. From monitoring to enforcement is the staged move through quarantine to full enforcement, and the point at which a domain is actually protected rather than merely observed.

The rest answer one question each. Some explain a standard: how the three records divide the work between them, what every tag in a DMARC record does and what it quietly defaults to when you leave it out, or how SPF syntax behaves once a domain runs into the ten-lookup limit. Others start where most people actually start — an error message from a checker, a report full of failures, or a client asking why their invoices went to spam. If that is you, read the guide that matches the symptom first, then come back to the route above; fixing one sender is worth little if the policy never moves off monitoring.