Glossary · Email
DMARC
A published policy telling receiving servers what to do with mail that fails SPF and DKIM, and where to send reports.
DMARC ties the other two together. It requires that a passing SPF or DKIM result also aligns with the visible From domain, then states a policy: none (monitor only), quarantine, or reject. It also names an address for aggregate reports.
A policy of reject is the strongest anti-spoofing setting a domain can publish: it asks the world to throw away mail that impersonates it. A policy of none means the domain is only watching.
In domain intelligence, the DMARC policy is a useful maturity signal. Domains used in phishing frequently have no DMARC at all, because the people registering them are not trying to protect the name.