DMARC is a short line of text on your domain that tells other mail servers what to do with email that claims to be from you but fails the security checks. It does two jobs for a business:
- It helps your real email reach inboxes. Gmail, Yahoo and Outlook now expect businesses to have it.
- It stops scammers pretending to be you. Fake invoices “from” your domain get blocked instead of delivered.
How DMARC works
DMARC sits on top of two other checks:
- SPF checks whether the server sending the email is on your list of allowed senders.
- DKIM checks the email’s digital signature.
DMARC then asks: does the email pass SPF or DKIM, and does that match the address in the “From” line? If not, it applies the policy you’ve chosen.
The three policies
| Policy | What happens to email that fails | When to use it |
|---|---|---|
p=none |
Delivered as normal; you just get reports | When you’re first setting up |
p=quarantine |
Sent to junk | Once your real email passes |
p=reject |
Blocked completely | The strongest protection |
A record with p=none doesn’t protect you from spoofing. It’s a starting point, not the finish line.
What a DMARC record looks like
It’s a TXT record on _dmarc.yourdomain.co.nz, for example:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.co.nz
v=DMARC1says it’s a DMARC record.p=noneis the policy.rua=is where daily summary reports are sent. They show every server sending email as your domain.
Setting it up safely, step by step
- Make sure SPF and DKIM are working first. Run our free email check. If SPF is missing, see how to add an SPF record.
- Add DMARC with
p=noneand a reporting address. Log in to wherever your domain’s DNS is managed (your registrar, web host or Cloudflare), add a TXT record with the host_dmarcand the value above. - Read the reports for two to four weeks. Look for any service of yours that’s failing, such as Xero, your website form or a newsletter tool, and fix it.
- Move to
p=quarantine, then later top=reject.
Jumping straight to p=reject before step 3 can block your own invoices, so don’t skip the reports.
Common mistakes
- Two DMARC records. Only one is allowed; with two, neither works.
- Putting it on the wrong name. It must be on
_dmarc.yourdomain, not on the domain itself. - Staying on
p=noneforever. Many businesses add DMARC once and never tighten it.
Rather we fixed it? Emails going to spam: fix: $195 + GST. You pay once it's fixed.