What DMARC adds on top of SPF and DKIM
SPF and DKIM each prove something about a message, but neither checks the domain the recipient actually sees in the From header. DMARC closes that gap. It requires that the domain which passed SPF or DKIM aligns with the From domain, and it tells receivers what to do when that fails: deliver anyway (none), send to spam (quarantine) or refuse (reject).
It also asks receivers to send you aggregate reports describing every source sending as your domain and whether it passed. For a cold email operation, DMARC is how you stop lookalike spoofing and how you notice a misconfigured tool before it burns a domain.
_dmarc.yourdomain.com TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100Moving from p=none to quarantine to reject
Start at p=none with a rua address. Nothing changes for delivery, but within a few days you will receive XML reports listing every IP that sent mail using your domain. Check that your mailbox provider, sending tool and any CRM all pass with alignment. Once only expected sources appear and they all pass, change to p=quarantine.
Run at quarantine for a few weeks. If nothing legitimate is being quarantined, switch to p=reject. Gmail and Yahoo require at least p=none from bulk senders, but receivers give more credit to enforced policies, and reject is the only setting that fully stops spoofing.
- Use pct=25 or pct=50 to roll out quarantine gradually if you are nervous.
- Set sp= if subdomains need a different policy; otherwise they inherit p.
- Keep adkim and aspf relaxed unless every sender uses the exact From domain.
- Re-read reports whenever you add a new sending tool.
Reading the tags that matter
The record is a list of tag=value pairs separated by semicolons. v must be DMARC1 and must come first. p is the only other required tag. rua takes one or more mailto: addresses for aggregate reports. pct limits how much failing mail the policy applies to. adkim and aspf switch alignment between relaxed (subdomains count) and strict (exact match). Everything else is optional and rarely needed.
A common mistake is sending reports to a third-party address without the authorisation record that domain must publish. Another is adding two DMARC records, which makes the policy undefined. The checker flags both, along with typos that turn a real tag into an unknown one that receivers ignore.
DMARC for cold email domains
Outreach domains are frequent spoofing targets because they are new and rarely monitored. A reject policy costs nothing once your own mail aligns, and it removes a whole class of reputation damage. Because most cold email setups send through Google Workspace or Microsoft 365 with DKIM enabled, alignment is normally already in place.
InboxOne publishes SPF, DKIM and a DMARC record on every domain it provisions, so a domain is protected from the first send. If you manage DNS yourself, use the generator to build the record and this checker to confirm it after propagation.

