What DMARC adds on top of SPF and DKIM
SPF and DKIM each prove something about a message, but neither checks that the proof relates to the address the recipient actually sees. DMARC closes that gap: it requires SPF or DKIM to pass and to align with the From domain, then tells receivers what to do when both fail. It also sends you reports, which is the only reliable way to discover every tool sending as your domain.
The record lives at _dmarc.yourdomain.com as a TXT record. A minimal, useful one looks like this.
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comChoosing between none, quarantine and reject
p=none is a monitoring mode: nothing changes for recipients, but you receive reports. p=quarantine asks receivers to put failing mail in spam. p=reject asks them to refuse it. Gmail and Yahoo require a DMARC record from bulk senders and treat enforcement (quarantine or reject) as a sign of a well-run domain.
- New domains that only send from one mailbox provider with DKIM can usually go straight to p=reject.
- Domains with a history of tools and integrations should start at p=none and read reports for a few weeks.
- Use pct to phase in enforcement: pct=25 applies the policy to a quarter of failing mail and the weaker policy to the rest.
- Set sp=reject when subdomains never send mail, so nobody can spoof them either.
Aggregate and forensic reports
The rua tag lists where receivers send aggregate reports: daily XML files summarising every IP that sent as your domain, and whether SPF and DKIM passed and aligned. The ruf tag requests forensic reports, per-message samples that few receivers still send and that can contain message content. For most teams, rua alone is enough.
If the report address is on a different domain than the one publishing the record, the receiving domain must publish an authorisation record at yourdomain.com._report._dmarc.reportdomain.com containing v=DMARC1. Hosted DMARC report services do this automatically.
Alignment modes and cold email tools
Relaxed alignment (the default) accepts a DKIM signing domain or SPF envelope domain that is the From domain or one of its subdomains. Strict requires an exact match. Cold email platforms send through your own mailbox provider, so the From domain, DKIM domain and SPF domain match and relaxed alignment passes cleanly.
Problems appear when a tool sends from its own infrastructure with a different envelope domain and no custom DKIM; the message fails alignment and an enforcing policy quarantines it. Check the reports before tightening, and keep alignment relaxed unless you have a specific reason. InboxOne domains come with a DMARC record already in place so the first campaign starts authenticated.

