Blog

3

min read

Admin

DMARC Policy Explained: none, quarantine or reject?

DMARC Policy Explained: none, quarantine or reject?

DMARC Policy Explained: none, quarantine or reject?

Which DMARC policy should you use? How none, quarantine and reject differ, and a safe rollout plan for cold email sending domains.

A DMARC policy tells receiving servers what to do with email that fails authentication. There are three: none (monitor only), quarantine (send to spam) and reject (block). Start with none, read the reports, fix your senders, then move to quarantine and finally reject.

To see what policy your domain has now, run it through the free Rhycon email deliverability checker.

What DMARC does

DMARC sits on top of SPF and DKIM. It checks that at least one of them passes and that the passing domain matches the domain in your visible From address. That match is called alignment. DMARC also gives you reports showing who is sending email as your domain.

The record is a TXT record at _dmarc.yourdomain.com. A starter record looks like this:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

The three policies

p=none

Monitor only. Nothing is blocked, but you start receiving reports. This is where everyone should begin. It also satisfies the minimum DMARC requirement for Google and Yahoo bulk senders.

p=quarantine

Failing mail is treated as suspicious and usually goes to the spam folder. Move here once your reports show every legitimate sender passes.

p=reject

Failing mail is refused outright. This gives the strongest protection against spoofing and is the end goal for your main domain.

Why this matters for cold email

Since 2024, Gmail and Yahoo have required a DMARC record for anyone sending in bulk, and Microsoft has tightened rules for Outlook too. A missing DMARC record on a sending domain is a red flag, and a lot of cold email domains have none at all. Adding a valid record is a few minutes of work and removes an easy reason for filters to distrust you.

How to roll it out safely

  1. Publish p=none with an address that receives reports (rua).

  2. Wait two to four weeks and read the reports. Use a free DMARC report viewer, because the raw XML is unreadable.

  3. Fix every legitimate sender that fails SPF or DKIM alignment.

  4. Move to p=quarantine. You can use pct=25 to apply it to a quarter of failing mail first, then raise it.

  5. Move to p=reject once you are confident.

Tags you will see

  • p: the policy for your domain.

  • sp: the policy for subdomains. If missing, subdomains inherit p.

  • rua: where aggregate reports are sent.

  • pct: the percentage of failing mail the policy applies to.

  • adkim and aspf: strict (s) or relaxed (r) alignment. Relaxed is the default and is fine for most.

What to use on cold sending domains

For a dedicated cold sending domain, start at p=none with a report address, and move to quarantine once you know only your mailboxes send from it. These domains have one or two senders, so the rollout is quick. If you would rather not handle this for every domain yourself, see Rhycon's managed infrastructure, which uses Rhycon-owned domains and mailboxes for your outreach.

Related guides: SPF lookup limit and DKIM record not found.

DMARC FAQs

Which DMARC policy should I use?

Start with none. Move to quarantine and then reject once your reports show all real senders pass.

Will p=none hurt my deliverability?

No. It does not block anything. It only turns on reporting and meets the basic requirement.

Do I need DMARC on every sending domain?

Yes. Each domain you send from should have its own record, or inherit one from a parent domain.

Why is DMARC failing when SPF and DKIM pass?

Because of alignment. The domain that passed is not the same as your From domain. Set up custom DKIM and SPF for the sending tool.

Ready to book more meetings?

Good AI Tools