How to Set Up DMARC
Follow this safe rollout: verify SPF and DKIM on all sending services, publish DMARC at p=none, review aggregate reports for 2–4 weeks, then move to p=quarantine and p=reject.
Step 1: Audit SPF and DKIM
Before publishing DMARC, ensure every legitimate sender (Microsoft 365, Google Workspace, Mailchimp, SendGrid, etc.) passes SPF and/or DKIM. Use our free DMARC checker and SPF checker.
Step 2: Publish DMARC at p=none
With QuickDMARC Managed DMARC, publish one CNAME at _dmarc.yourdomain.com pointing to yourdomain.com._report._dmarc.quickdmarc.com. QuickDMARC hosts the live TXT record and receives reports.
Step 3: Monitor aggregate reports
Review RUA reports in the QuickDMARC dashboard for 2–4 weeks. Identify failing sources: unauthorized senders, misconfigured third-party services, or forwarding issues.
Step 4: Move to enforcement
- Week 1–2:
p=none— monitor only - Week 3:
p=quarantinewithpct=25, then increase - Week 4+:
p=rejectwhen all legitimate senders pass
Implementation timeline
DNS setup: under 5 minutes. Full monitoring-to-enforcement rollout: typically 2–4 weeks. Reference: RFC 7489.
Common mistakes
- Publishing
p=rejectbefore validating all senders (blocks legitimate mail) - Exceeding 10 DNS lookups in SPF (causes SPF permerror)
- Forgetting third-party marketing/CRM senders in SPF and DKIM