Browse the Learning Center
Get to p=reject
The full route from an unprotected domain to an enforced policy, in the order the work actually happens.
5 steps
What DMARC actually doesPolicy, alignment, and what a receiving server checks.Step 1 of 5
Publish your first recordWhere the record goes in DNS and why it starts at p=none.Step 2 of 5
Read your first reportFind every sender using your domain, legitimate or not.Step 3 of 5
Fix SPF before you tightenClear PermError and the 10-lookup limit so real mail survives.Step 4 of 5
Move to quarantine, then rejectStage the policy without losing legitimate mail.Step 5 of 5