Skip to content

Email-domain security

What is DMARC?

The DMARC record at _dmarc under the domain: whether it exists and parses, how strict its policy is, whether it applies to all mail and whether it asks for reports.

Part of the External Security Check. Free during the preview.

What it checks

The DMARC record at _dmarc under the domain: whether it exists and parses, how strict its policy is, whether it applies to all mail and whether it asks for reports.

A pass means: A DMARC policy tells receivers what to do with mail that fails checks.

Possible findings

No DMARC policy

Severity: MediumConfidence: ConfirmedKind: Security issue

What we found

No DMARC record was found at _dmarc for the domain.

Why it matters

DMARC tells receivers what to do with mail that fails SPF and DKIM, and sends you reports about who sends as your domain. Without it, spoofed mail is much more likely to be delivered.

How to fix it

Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.

DMARC is in monitoring mode

Severity: LowConfidence: ConfirmedKind: Recommended hardening

What we found

The DMARC policy is p=none, which reports on failures but does not stop them.

Why it matters

Monitoring mode is the right first step, but it does not protect anyone from spoofed mail until the policy is raised.

How to fix it

Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.

DMARC record has errors

Severity: MediumConfidence: High confidenceKind: Security issue

What we found

The DMARC record could not be parsed.

Why it matters

Receivers ignore a malformed DMARC record, so the domain is treated as having no policy.

How to fix it

Correct the record. It must start with v=DMARC1; followed by a p= tag (none, quarantine or reject).

DMARC applies to only part of the mail

Severity: InformationConfidence: ConfirmedKind: Recommended hardening

What we found

The DMARC policy sets pct below 100.

Why it matters

Only a sample of failing mail is subject to the policy. This is useful while rolling out, but leaves the rest unprotected.

How to fix it

Remove the pct tag (it defaults to 100) once you are confident in the policy.

DMARC reports are not requested

Severity: InformationConfidence: ConfirmedKind: Recommended hardening

What we found

The DMARC record has no rua tag, so you receive no aggregate reports.

Why it matters

Without reports you cannot see who is sending mail as your domain, or whether legitimate mail is failing.

How to fix it

Add rua=mailto: with an address or a DMARC reporting service.

References