Rigcheck

Guides

DMARC p=none vs quarantine vs reject: which policy to use and when

Every DMARC record has a policy, set with the p= tag. It tells receiving mail servers what to do with a message that claims to be from your domain but fails authentication. There are three choices:

  • p=none: deliver it anyway, and just report it to you.
  • p=quarantine: deliver it to the spam folder.
  • p=reject: refuse it, so it never arrives.

Most domains should end up at quarantine or reject, but jumping there too early can block your own legitimate email. This guide explains what each policy does in practice and how to move between them safely.

Not sure what your current policy is? Rigcheck reads your DMARC record and tells you what it means.

Check your domain

How DMARC decides pass or fail

DMARC builds on SPF and DKIM. A message passes DMARC when either of these is true:

  • SPF passes, and the domain it checked (the hidden Return-Path) matches the domain in the visible From address.
  • DKIM passes, and the signing domain (the d= value in the signature) matches the From domain.

That "matches" requirement is called alignment, and it's where most legitimate mail fails. A newsletter tool can pass SPF and DKIM perfectly for its own domain and still fail DMARC for yours. By default, alignment is relaxed, so a subdomain like mail.yourdomain.com counts as matching yourdomain.com.

In practice, the most reliable way to pass DMARC is to turn on DKIM signing with your own domain in every service that sends email for you.

What each policy means

PolicyMail that fails DMARCUse it when
p=noneDelivered normally. You get reports.You're starting out and need to see who sends as your domain.
p=quarantineSent to the spam folder.Your reports show all legitimate mail passing, and you want protection with a safety net.
p=rejectRefused outright and never delivered.You're confident every legitimate sender is authenticated.

p=none is monitoring, not protection

With p=none, anyone can still send email pretending to be you, and it gets delivered. What you gain is visibility: receivers send you daily reports listing every server that sent mail using your domain and whether it passed.

It still matters. Gmail, Yahoo and Microsoft require bulk senders to publish a DMARC record, and p=none meets that requirement. But it's meant to be the first step, not where you stay.

p=quarantine is enforcement with a safety net

Failing mail goes to spam instead of the inbox. If you missed a legitimate sender, its messages are still recoverable from spam folders while you fix the setup. For many organizations, this is a comfortable long-term setting.

p=reject is full protection

Failing mail is refused during delivery, so spoofed messages never reach anyone. This is the strongest protection against phishing that impersonates your domain. The trade-off is that a misconfigured legitimate sender's mail also disappears, with only a bounce to the sending service.

Which policy should you use?

Your domain never sends email

Go straight to p=reject. Parked domains, redirect domains and brand-protection domains are popular targets for spoofing precisely because nobody watches them. Pair it with an SPF record that authorizes nothing:

Name: _dmarc    Value: v=DMARC1; p=reject
Name: @         Value: v=spf1 -all

Your domain sends email and has no DMARC yet

Start at p=none with reporting turned on, then follow the rollout steps below. Plan on reaching enforcement within a month or two.

You've been on p=none for months

This is the most common situation, and it's worth fixing. Many domains add p=none to meet a requirement and never come back to it, which leaves them unprotected indefinitely. If your reports show your legitimate mail passing, you're ready to move to quarantine.

A safe path from none to reject

  1. Publish p=none with a reporting address. Use an inbox you'll actually look at, or a DMARC reporting service that turns the reports into readable summaries.
    v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
  2. Watch reports for two to four weeks. You're looking for every service that sends as your domain: your mailbox provider, newsletter tool, help desk, billing system, CRM. Monthly mail like invoices takes a full cycle to show up.
  3. Fix each legitimate sender that fails. Usually that means turning on DKIM for your domain in that service's settings. Sources you don't recognize are either spoofing or a forgotten tool, and you should find out which.
  4. Move to p=quarantine. If you want to be extra careful, apply it to part of your mail first with pct=, then raise it.
    v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@yourdomain.com
  5. Raise to 100%, then move to p=reject once a few weeks pass without legitimate mail failing.
    v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com

Keep the rua= reporting address even at p=reject. New tools get added over time, and reports are how you'll notice one that wasn't set up correctly.

Other tags worth knowing

  • sp= sets a separate policy for subdomains. Without it, subdomains follow your main p= policy.
  • pct= applies the policy to only a percentage of failing mail. It's a rollout tool. Don't leave it below 100 long term, since the rest of your failing mail is treated as p=none.
  • rua= is where daily aggregate reports go. If the address is at a different domain than the one you're protecting, that other domain has to publish a small DNS record authorizing it, or receivers won't send the reports. Reporting services handle this for you.
  • adkim= and aspf= switch alignment between relaxed (the default) and strict. Strict alignment rejects subdomain matches, and most domains should leave these alone.

Things that can break at p=reject

  • Services that rely on SPF alone. Any sender without DKIM for your domain is one configuration change away from failing. Make sure DKIM is on everywhere before enforcing.
  • Forwarding. When mail is forwarded, SPF usually fails because the forwarding server isn't on your list. DKIM normally survives, which is another reason it matters.
  • Mailing lists. Lists that add a footer or change the subject line can break the DKIM signature. Most modern list software works around this by rewriting the From address, but older lists may bounce your messages.

None of these are reasons to stay at p=none forever. They're reasons to read your reports before you enforce.

A bonus for enforced domains

BIMI, the standard that shows your logo next to your messages in Gmail and other inboxes, requires a DMARC policy of quarantine or reject applied to all mail. It's one more reason to finish the rollout.

Check your DMARC policy now. Rigcheck shows your current policy and gives you the exact record for your next step.

Check your domain

More guides