caduh

What is DMARC (and why you should care)

1 min read

DMARC tells inboxes what to do when email fails SPF/DKIM checks — and sends you reports so you can fix issues.

DMARC = Domain-based Message Authentication, Reporting & Conformance.

  • Authentication: Requires messages to pass SPF or DKIM (or both), aligned to your domain.
  • Policy: Tell receivers what to do if auth fails: p=none | quarantine | reject.
  • Reporting: You get aggregate XML reports so you see who’s sending on your behalf.

Start safe:

  1. Publish p=none and monitor reports via a DMARC service.
  2. Fix legitimate senders (newsletters, support tools) to pass SPF/DKIM with alignment.
  3. Gradually move to quarantine then reject.

Record (example):
_dmarc.caduh.com TXT "v=DMARC1; p=none; rua=mailto:[email protected]"