What DMARC actually does
SPF says which servers may send for you. DKIM signs your messages. DMARC is the instruction telling receiving servers what to do when those checks fail: nothing, quarantine, or reject.
Without it, a forged message claiming to come from your domain arrives looking entirely normal. Invoice fraud aimed at your customers relies on exactly this.
Publish it in this order
- Start at monitoring only. Add a TXT record at
_dmarc.yourdomain.comwith the valuev=DMARC1; p=none; rua=mailto:you@yourdomain.com. This changes nothing about delivery and starts reports arriving. - Read the reports for a few weeks. They will show every system sending as you, including ones you forgot: invoicing tools, booking systems, the CRM, an old newsletter platform.
- Authorise the legitimate ones in SPF and DKIM until they pass.
- Then move to quarantine, and later to reject. Only once nothing legitimate is failing.
The mistake worth avoiding
Publishing p=reject immediately because a checklist said to. Every sender you have not authorised then has its mail rejected, and because the rejection happens at the receiving end, you will not see errors. You will see silence, and you will attribute it to customers not replying.
What to write down
Which systems are authorised to send as you. That list changes whenever someone signs up for a new tool, and it is the thing that later breaks mail without anyone connecting the two events.
DMARC accepts either SPF or DKIM, so publishing DKIM is what makes a strict policy safe to run.
The whole subject in five chapters: the DMARC field guide.