DMARC Policy and Alignment
Configure DMARC alignment, p=none, quarantine, reject, reporting, and rollout steps for transactional email domains.
TL;DR
DMARC passes when either SPF or DKIM passes and aligns with the visible From domain. Start with p=none, read aggregate reports, fix legitimate senders, then move toward quarantine or reject deliberately.
What you will learn
- Understand relaxed and strict DMARC alignment
- Move safely from monitoring to enforcement
- Use aggregate reports to find broken senders
What DMARC checks
DMARC sits on top of SPF and DKIM. It checks whether an authenticated domain aligns with the visible From domain.
A message can pass DMARC through either path:
- SPF passes and the SPF domain aligns with From.
- DKIM passes and the DKIM signing domain aligns with From.
If neither aligned path passes, the domain owner's DMARC policy tells receivers what action to consider.
Relaxed vs strict alignment
| Mode | Example | Result |
|---|---|---|
| Relaxed SPF | From example.com, Return-Path mail.example.com | Aligns |
| Strict SPF | From example.com, Return-Path mail.example.com | Does not align |
| Relaxed DKIM | From example.com, DKIM d=mail.example.com | Aligns |
| Strict DKIM | From example.com, DKIM d=mail.example.com | Does not align |
Use strict alignment when you control every legitimate sender. Use relaxed alignment when legitimate subdomains need to send.
Example DMARC record
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=s; aspf=s"
p=none monitors without asking receivers to quarantine or reject failing mail. That is the right starting point for most production domains.
Rollout sequence
- Publish SPF and DKIM for every legitimate sender.
- Publish DMARC with
p=none. - Collect aggregate reports.
- Group sources by pass, fail, and unknown.
- Fix legitimate sources that fail alignment.
- Move to stricter policy only after reports are clean.
- Keep monitoring after enforcement.
If you receive many reports, use DMARC reports or the DMARC parser to avoid manual XML review.
What changed in 2026
DMARC was updated in May 2026. RFC 9989 defines the core protocol, RFC 9990 defines aggregate reporting, and RFC 9991 defines failure reporting. RFC 7489 is obsolete.
The DNS record still starts with v=DMARC1. Do not publish v=DMARC2.
Gmail and Yahoo expectations
Large mailbox providers increasingly expect authenticated and aligned mail, especially for bulk senders. Gmail sender guidelines and Yahoo Sender Hub both emphasize SPF, DKIM, DMARC alignment, low spam complaint rates, and easy unsubscribe handling.
Transactional teams should treat these as baseline operational controls, even if they are not running marketing campaigns.
References
Frequently asked questions
- Does DMARC require both SPF and DKIM to pass?
- No. DMARC can pass when either SPF or DKIM passes and aligns with the visible From domain.
- Is RFC 7489 still the current DMARC reference?
- No. As of May 2026, RFC 9989, RFC 9990, and RFC 9991 obsolete RFC 7489.
Related guides
Put the guide into production
Postscale brings sending, inbound processing, DMARC reporting, and masked addresses behind one API so the operational pieces stay connected.