DMARC Quarantine
DMARC p=quarantine asks receivers to treat failing messages with suspicion—typically spam or junk folders—while you continue collecting reports.
What this policy does
Failing mail should not land in the primary inbox when receivers honor quarantine. Exact handling varies by mailbox provider.
v=DMARC1; p=quarantine; pct=100; rua=mailto:[email protected]When to use it
Use quarantine after reports show most legitimate mail passes DMARC, or stage with pct while you finish ESP fixes.
Troubleshooting before you change policy
Check aggregate reports for unknown sources, SPF PermError, missing DKIM selectors, and From domains that do not match signing domains.
- Run a DMARC checker on the apex and major sending subdomains
- Validate SPF lookup count under 10
- Confirm DKIM for Microsoft 365 / Google / ESPs
- Fix or retire shadow IT senders
Microsoft 365 & Google Workspace
Policy lives in your public DNS, not inside the M365 or Google admin center. Ensure Exchange Online and Google Workspace mail are aligned before quarantine/reject.
How QuickDMARC helps
QuickDMARC monitors pass/fail trends and helps you change Managed DMARC policy when ready—without guessing from incomplete mailbox samples.
Frequently asked questions
Does DMARC Quarantine stop spoofing by itself?
It substantially reduces direct spoofing when receivers honor the policy and your legitimate mail stays aligned.
Do I still need rua?
Yes. Keep aggregate reporting enabled through every policy stage.
Related policies?
See p=none, quarantine, and reject guides plus the overall DMARC policy page.