DMARC is a published instruction telling receiving mail servers what to do when a message claiming to be from your domain fails authentication. Enabled in monitoring mode it costs nothing and reports what is happening. Switched straight to enforcement it can silently block legitimate mail sent on your behalf by systems nobody remembered.

The three records and what each does

They work together and are frequently confused with each other.

SPF and DKIM without DMARC means the checks happen and nothing is instructed. DMARC is the policy layer on top, and it is also the only one that sends you information.

The three policy settings

PolicyWhat receiving servers doWhen to use it
noneNothing different, but send reportsAlways first. Costs nothing and reveals what is sending as you
quarantineDeliver failures to junkOnce reports show all legitimate senders passing
rejectRefuse failures outrightOnce quarantine has run cleanly for a period

The sequence matters. Publishing reject on day one is the mistake, because you do not yet know what is sending mail on your behalf.

What the reports usually reveal

This is the genuinely useful part, and it surprises most businesses.

A domain that appears to send only from one mailbox turns out to send from several places: the accounting system issuing invoices, the booking tool sending confirmations, the website's contact form, a newsletter platform, a supplier sending on your behalf, and occasionally something set up years ago by someone no longer there.

Each of those needs to be authorised. Going to enforcement without knowing they exist means those messages start failing, and the failures are silent from your side. The invoices simply stop arriving, and the customer assumes you did not send one.

The migration path that works

Six to twelve weeks end to end for a small business. Rushing it is where the damage happens, and there is no benefit to arriving early.

The SPF limit that catches people

An SPF record may only trigger a limited number of lookups, and each service you authorise typically consumes at least one. Businesses using a mail provider, a newsletter tool, a booking system, and an accounting package can exceed the limit.

When that happens the record stops being evaluated properly and mail begins failing, which looks identical to a DMARC problem and is not. The fix is consolidation rather than adding more entries, and it is worth checking the count before authorising another service.

Why it is worth doing at all

Two reasons, one defensive and one practical.

The defensive one is that without an enforcement policy, anyone can send mail claiming to be from your domain. For a business sending invoices, that is a genuine exposure.

The practical one is delivery. Receiving providers increasingly weigh authentication when deciding whether mail reaches an inbox, and requirements have tightened for anyone sending in volume. A properly authenticated domain simply arrives more reliably, which matters for every quote and confirmation you send, as covered in email deliverability for small senders.

The part to get right first

Publish the monitoring policy today. It takes one record, changes nothing about delivery, and within a fortnight you will know exactly what is sending mail as your business.

Most businesses never find that out, and the report is worth having even if you never move beyond monitoring. It is the same principle as the listings audit: you cannot manage what you have never seen an inventory of.


Frequently asked questions

What is DMARC?

A published policy telling receiving mail servers what to do when a message claiming to be from your domain fails authentication, and asking them to report what they saw.

What is the difference between SPF, DKIM and DMARC?

SPF lists which servers may send for your domain, DKIM signs messages to prove they are genuine, and DMARC tells receivers what to do when those checks fail. DMARC is also the only one that reports back.

Should I set DMARC to reject straight away?

No. Start at none, which changes nothing about delivery and produces reports. Most businesses discover several legitimate senders they had forgotten, and enforcing before authorising them blocks your own mail.

How long does it take to reach enforcement?

Six to twelve weeks for a small business: several weeks collecting reports, then quarantine, then reject. Rushing produces silent delivery failures and there is no benefit to arriving early.

Why would my own invoices stop arriving?

Because the system sending them was never authorised, and enforcement told receiving servers to reject anything failing authentication. The failure is silent, so the customer simply assumes no invoice was sent.

What is the SPF lookup limit?

An SPF record may only trigger a limited number of lookups, and each authorised service consumes at least one. Exceeding it stops the record being evaluated properly, which looks like a DMARC problem and is not.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Not sure what is sending email as your business?

We publish the monitoring policy, read the reports, and take you to enforcement in stages so nothing of yours gets blocked.

Start a Conversation