[domain]
1. Executive summary
2. Findings at a glance
3. What we found, in detail
Not sure about any of this? DNS changes affect live email — if anything here is unclear, don't guess. Work with a qualified IT partner who can apply these safely — share this report with them and they'll have everything they need.
4. Recommended fixes (copy-paste ready)
Apply these at your DNS host. Each record is shown in the format you'll find in most DNS providers (Cloudflare, GoDaddy, Namecheap, Route 53, etc.).
5. Safe rollout plan to full protection
We move in stages so legitimate mail is never caught in the crossfire. The 4-step timeline below is the overview; the Review phase is where the actual work happens — that's covered in detail underneath.
-
Week 1 — Monitor (
p=none). Publish DMARC in reporting mode. Receivers start sending you daily reports listing every IP that's claiming to send as your domain. No delivery impact. - Weeks 2–3 — Review. Read the reports, identify every legitimate sender, confirm they're authenticated. Don't move to quarantine until this is done.
-
Week 3–4 — Quarantine (
p=quarantine). Failing mail goes to spam instead of the inbox. Watch one more week for false positives. -
Week 4+ — Enforce (
p=reject). Spoofed mail is rejected at the receiver's gateway — never reaches inbox or spam. End state.
How to actually do the Review week
When you publish DMARC at p=none, mailbox providers (Gmail, Yahoo, Outlook, Apple, etc.) start sending you aggregate reports — daily XML files listing every source IP that's sent mail "as" your domain, with per-source SPF/DKIM/alignment results. They go to whatever address you set in the rua= tag.
The reports are raw XML — technically human-readable, but it's a slog. Use a free parser to turn them into a dashboard.
Recommended free DMARC monitoring tools
- dmarcian — most established. Free for up to 25k messages/month. Best UI for understanding what each IP is.
- Postmark DMARC Monitor — free, simple. Weekly email digest. Lowest effort to set up.
- EasyDMARC — free tier with daily reports and a clear dashboard.
- Valimail Monitor — free, enterprise-grade. More signal but heavier.
abc123@rep.dmarcian.com), and replace the rua= value in your DMARC record with it. From then on, reports go straight into a usable dashboard.
What to look for in your reports
Every aggregate report shows, per source IP:
- Volume — how many messages did this IP send claiming to be from your domain?
- SPF result — did the IP match your SPF record (pass) or not (fail)?
- DKIM result — was the message signed with a DKIM key for your domain?
- DMARC alignment — did the From: domain match the SPF/DKIM domain?
Three things to actively look for as you scan reports:
- Sources you recognize. Every IP should map back to one of YOUR tools — your mail provider, marketing platform, customer relationship management (CRM) tool, billing software, etc. If you don't recognize a sender, investigate before you lock down.
- Legitimate senders that are failing. Very common in Week 1. Examples: marketing tool that isn't DKIM-signing on your domain, a new CRM you forgot to add to SPF, employees forwarding mail to a personal Gmail breaking authentication. Each one needs to be fixed (or deliberately tolerated) before you move to quarantine.
- Suspicious / unknown sources. IPs from hosting providers or countries you don't operate from, sending small volumes, are usually spoofing attempts. These are the threats DMARC enforcement will block.
Build your sender inventory
Before flipping to quarantine, you should be able to list every legitimate source of mail "as" your domain. Walk this checklist and add anything you use:
- Primary mail provider (Google Workspace, Microsoft 365, Fastmail, etc.)
- Marketing email (Mailchimp, Constant Contact, HubSpot, ActiveCampaign, Klaviyo)
- Transactional email from apps (Stripe, Shopify, Calendly, etc.)
- CRM / sales tool (Salesforce, Pipedrive, HubSpot Sales, Zoho)
- Helpdesk / support (Zendesk, Freshdesk, Intercom, HelpScout)
- Invoicing / billing (QuickBooks, Wave, FreshBooks, Xero)
- Scheduling (Calendly, Acuity, SimplyBook)
- Website form notifications (your contact form, lead-gen forms)
- Workflow automation (Zapier, Make, n8n)
For each item above, confirm one of these is true:
- It's listed in your SPF record (you'll see an
include:for it), or - You added a CNAME they provided so they DKIM-sign as your domain, or
- Their From: address uses their own domain (e.g. notifications@stripe.com), not yours — in which case it's none of your DMARC's business.
Ready to move from p=none → p=quarantine?
You're ready when all of these are true:
- You've been collecting reports for at least 2 weeks
- You can identify every source IP in your reports (no unknowns)
- Every legitimate sender from your inventory is either authenticated (SPF or DKIM aligned) or uses its own domain
- DMARC alignment passes ≥95% for legitimate mail in the last 7 days of reports
- You're comfortable with mail from unrecognized sources going to the recipient's spam folder
If you check all five, apply Fix 3's quarantine variant, then watch reports for another week before the final step.
Ready to move from p=quarantine → p=reject?
You're ready when all of these are true:
- You've been at
p=quarantinefor at least 1 week - No one has reported a legitimate email going missing or landing in spam
- Reports show no new failing IPs you can't identify
- You have a process: someone owns adding new senders to SPF/DKIM going forward
At p=reject, spoofed mail is rejected at the recipient's gateway — it never reaches the inbox or spam. You're done.