veriastra_
Glossary · Email

DMARC

A published policy telling receiving servers what to do with mail that fails SPF and DKIM, and where to send reports.

DMARC ties the other two together. It requires that a passing SPF or DKIM result also aligns with the visible From domain, then states a policy: none (monitor only), quarantine, or reject. It also names an address for aggregate reports.

A policy of reject is the strongest anti-spoofing setting a domain can publish: it asks the world to throw away mail that impersonates it. A policy of none means the domain is only watching.

In domain intelligence, the DMARC policy is a useful maturity signal. Domains used in phishing frequently have no DMARC at all, because the people registering them are not trying to protect the name.