Email spoofing — sending mail that appears to come from your domain — is one of the cheapest attacks going, and one of the most damaging to a brand. DMARC is the control that finally lets you stop it, by telling the world exactly which servers may send as you and what to do with everything else.
DMARC builds on SPF and DKIM
SPF lists the servers allowed to send for your domain. DKIM adds a cryptographic signature that proves a message was not altered. DMARC ties the two together: it requires that the domain a recipient sees (the From address) aligns with a passing SPF or DKIM check, and it publishes a policy for what to do when that alignment fails.
The three policies
A DMARC record is a single DNS TXT entry. The policy you set determines how strictly receivers treat unauthenticated mail claiming to be from you.
- p=none — monitor only; nothing is blocked, but you receive reports.
- p=quarantine — unauthenticated mail is sent to spam.
- p=reject — unauthenticated mail is refused outright.
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc@example.com; adkim=s; aspf=s"Rolling out safely
Never jump straight to p=reject. Start at p=none and read the aggregate reports for two to four weeks to discover every legitimate service that sends as you — your CRM, invoicing tool, help desk, and marketing platform. Once each of those is passing SPF or DKIM, move to quarantine, watch again, then finally to reject.
What p=reject buys you
At p=reject, a receiver that gets mail failing authentication and claiming to be from your domain simply refuses it. Phishing campaigns that impersonate your brand stop reaching inboxes, protecting both your customers and your sender reputation. Airfree Clouds flags your live DMARC policy in the domain dashboard so you always know where you stand.
Ready to get started?
Register a domain, set up business email, and manage DNS — all in one place, privacy-first.
Search domains →