Reviewed by: QuickDMARC Security Team · Email Authentication Specialists ·

How to Set Up DMARC

Follow this safe rollout: verify SPF and DKIM on all sending services, publish DMARC at p=none, review aggregate reports for 2–4 weeks, then move to p=quarantine and p=reject.

Step 1: Audit SPF and DKIM

Before publishing DMARC, ensure every legitimate sender (Microsoft 365, Google Workspace, Mailchimp, SendGrid, etc.) passes SPF and/or DKIM. Use our free DMARC checker and SPF checker.

Step 2: Publish DMARC at p=none

With QuickDMARC Managed DMARC, publish one CNAME at _dmarc.yourdomain.com pointing to yourdomain.com._report._dmarc.quickdmarc.com. QuickDMARC hosts the live TXT record and receives reports.

Step 3: Monitor aggregate reports

Review RUA reports in the QuickDMARC dashboard for 2–4 weeks. Identify failing sources: unauthorized senders, misconfigured third-party services, or forwarding issues.

Step 4: Move to enforcement

  1. Week 1–2: p=none — monitor only
  2. Week 3: p=quarantine with pct=25, then increase
  3. Week 4+: p=reject when all legitimate senders pass

Implementation timeline

DNS setup: under 5 minutes. Full monitoring-to-enforcement rollout: typically 2–4 weeks. Reference: RFC 7489.

Common mistakes