Land your Emails in the Inbox

We make it simple for companies to improve and monitor their email deliverability.

2x Email Deliverability equals

2x Open rates

2x Meetings Booked

2x Revenue

Glossary

Email authentication glossary

Every tag and mechanism across DMARC, SPF, and DKIM — explained in one place.

Every tag you can include in a DMARC record and what each one controls.

vVersion
The Version tag is essential in a DMARC record and must strictly be set to ‘DMARC1’. If this value is not correctly specified or if the tag is absent, the DMARC record will not be considered valid and will be disregarded.
pDMARC policy
The DMARC policy setting is crucial and accepts three possible values: ‘none’, ‘quarantine’, or ‘reject’. By default, it is set to ‘none’, which means it doesn’t actively intervene with emails that fail authentication. This setting primarily serves to gather DMARC reports, aiding in understanding the existing email traffic and its authentication status. On the other hand, the ‘quarantine’ option flags unauthenticated emails as dubious, and ‘reject’ outright prevents their delivery.
ruaAggregate report destination
The destination for sending aggregate reports is specified using a ‘mailto:’ URI, which Email Service Providers (ESPs) utilize to dispatch failure reports. While this tag is not mandatory, omitting it means you will not receive any reports.
rufForensic report destination
The destination for Forensic (Failure) report transmission is designated by a ‘mailto:’ URI, which is employed by Email Service Providers (ESPs) for the delivery of failure reports. Although this tag is not obligatory, failing to include it will result in not receiving any reports.
spSubdomain policy
The policy for subdomains defaults to inheriting the main domain’s policy tag (p=), as previously described, unless explicitly stated otherwise. Similar to the domain policy, the permissible values for subdomains are ‘none’, ‘quarantine’, or ‘reject’. However, this option is not commonly employed in current practices.
adkimDKIM alignment
The alignment of the DKIM signature, indicated by this tag, refers to the congruence between the DKIM domain and the originating domain in the ‘Header From’. The acceptable values for this tag are ‘r’ for relaxed and ‘s’ for strict. The default setting, ‘r’, permits a partial match between these domains, whereas the ‘s’ setting demands an exact match of the domains.
aspfSPF alignment
This tag pertains to the SPF alignment, which concerns the compatibility between the SPF domain (the sender) and the domain in the ‘Header From’. It allows two settings: ‘r’ for relaxed and ‘s’ for strict. By default, it is set to ‘r’, which tolerates a partial match between the domains. In contrast, the ‘s’ setting necessitates an exact correspondence of the domains.
foForensic reporting options
The options for forensic reporting include ‘0’, ‘1’, ‘d’, and ‘s’. The default setting is ‘0’, which triggers a forensic report only when both SPF and DKIM alignments do not pass. Use ‘1’ if the outcome of either SPF or DKIM is anything other than a pass. The option ‘d’ is selected to generate a report specifically for DKIM validation failures, and ‘s’ is used for SPF-related issues. To actually receive these forensic reports, it’s necessary to specify the ‘ruf’ tag.
rfFailure report format
The format for failure report generation can be set to either ‘afrf’ or ‘iodef’, as these are the two permissible options.
pctPercentage (historic)
The legacy Percentage tag asked receivers to apply a quarantine or reject policy to only part of the mail that failed DMARC. RFC 9989 removed pct because receivers implemented partial enforcement inconsistently. New records should omit it and stage rollout with aggregate reports, whole-policy changes, and low-volume subdomains.
riReporting interval
The Reporting interval specifies how often XML reports are received, measured in seconds. The standard setting is 86400 seconds, which equates to daily reporting. However, it’s important to note that despite the specified interval, Internet Service Providers (ISPs) typically send these reports on their own schedules, which in most cases, is also once a day.
Official Partners

Improve results with all your email tools

GmailGoogle WorkspaceMailchimpAmazon SESMailerLiteActiveCampaignMailjetDripSendGridSMSMTPConvertKitHubSpotBeehiivZohoOutlookSalesforceMailguniCloud

Logos provided by Logo.dev

Don't land in Spam, close more sales

Instant Results

Start seeing results immediately after implementation of your free report and get deliverability improvements for the years to come.

Save Time

No need to spend time configuring and monitoring complicated software. Palisade is made for non developers and our team is there to do the work with you.

Easy Setup

We handle all the necessary configuration and compliance work for you, ensuring that you can focus on growing your business without any worries or hassle.

“All our emails started magically reaching the inbox in less than a week”

Marc-André Campagna — CEO — gaiia (YC 2021)

Set it, forget it, and grow your business.

1 domain free up to 1,000 emails/month