Auth

DMARC Policy and Alignment

Configure DMARC alignment, p=none, quarantine, reject, reporting, and rollout steps for transactional email domains.

Updated

TL;DR

DMARC passes when either SPF or DKIM passes and aligns with the visible From domain. Start with p=none, read aggregate reports, fix legitimate senders, then move toward quarantine or reject deliberately.

What you will learn

  • Understand relaxed and strict DMARC alignment
  • Move safely from monitoring to enforcement
  • Use aggregate reports to find broken senders

What DMARC checks

DMARC sits on top of SPF and DKIM. It checks whether an authenticated domain aligns with the visible From domain.

A message can pass DMARC through either path:

  1. SPF passes and the SPF domain aligns with From.
  2. DKIM passes and the DKIM signing domain aligns with From.

If neither aligned path passes, the domain owner's DMARC policy tells receivers what action to consider.

Relaxed vs strict alignment

ModeExampleResult
Relaxed SPFFrom example.com, Return-Path mail.example.comAligns
Strict SPFFrom example.com, Return-Path mail.example.comDoes not align
Relaxed DKIMFrom example.com, DKIM d=mail.example.comAligns
Strict DKIMFrom example.com, DKIM d=mail.example.comDoes not align

Use strict alignment when you control every legitimate sender. Use relaxed alignment when legitimate subdomains need to send.

Example DMARC record

_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=s; aspf=s"

p=none monitors without asking receivers to quarantine or reject failing mail. That is the right starting point for most production domains.

Rollout sequence

  1. Publish SPF and DKIM for every legitimate sender.
  2. Publish DMARC with p=none.
  3. Collect aggregate reports.
  4. Group sources by pass, fail, and unknown.
  5. Fix legitimate sources that fail alignment.
  6. Move to stricter policy only after reports are clean.
  7. Keep monitoring after enforcement.

If you receive many reports, use DMARC reports or the DMARC parser to avoid manual XML review.

What changed in 2026

DMARC was updated in May 2026. RFC 9989 defines the core protocol, RFC 9990 defines aggregate reporting, and RFC 9991 defines failure reporting. RFC 7489 is obsolete.

The DNS record still starts with v=DMARC1. Do not publish v=DMARC2.

Gmail and Yahoo expectations

Large mailbox providers increasingly expect authenticated and aligned mail, especially for bulk senders. Gmail sender guidelines and Yahoo Sender Hub both emphasize SPF, DKIM, DMARC alignment, low spam complaint rates, and easy unsubscribe handling.

Transactional teams should treat these as baseline operational controls, even if they are not running marketing campaigns.

References

Frequently asked questions

Does DMARC require both SPF and DKIM to pass?
No. DMARC can pass when either SPF or DKIM passes and aligns with the visible From domain.
Is RFC 7489 still the current DMARC reference?
No. As of May 2026, RFC 9989, RFC 9990, and RFC 9991 obsolete RFC 7489.

Related guides

Put the guide into production

Postscale brings sending, inbound processing, DMARC reporting, and masked addresses behind one API so the operational pieces stay connected.