Email & SMTP

Configure DMARC

Publish a correct DMARC record so your domain stops being an easy target for email spoofing.

The Problem

You've probably already got SPF and maybe DKIM in place, but without a DMARC record your domain has no policy telling mailbox providers what to do with mail that fails those checks. That means spoofed emails using your domain can still land in someone's inbox, and you get zero visibility into who's doing it.

About this problem

DMARC is the piece that ties SPF and DKIM together and tells receiving mail servers what to actually do when a message fails those checks — without it, a failed SPF or DKIM check is just informational, and spoofed mail can still land in an inbox looking like it came from you.

It's commonly missing because SPF (and sometimes DKIM) get set up early for deliverability, while DMARC is treated as an afterthought or something only large companies need. That changed in 2024, when Google and Yahoo started requiring DMARC for anyone sending bulk mail to their users — a lot of people now need this specifically because a sending platform or migration has started flagging its absence.

What's Included

What's NOT Included

How It Works

  1. Pull your current SPF and DKIM records and confirm both actually validate and align with the domain used in your From: address.
  2. Decide a sensible starting policy (monitoring-only with p=none, or straight to quarantine) based on how confident we are every sending source is already accounted for.
  3. Draft the DMARC TXT record itself — policy, alignment mode for SPF and DKIM, and an rua address so aggregate reports actually go somewhere you can read them.
  4. Publish the record at _dmarc.yourdomain.com and confirm it resolves correctly from outside your own network.
  5. Send live test messages from every system that sends on your behalf — your main inbox, CRM, invoicing tool, newsletter platform — and confirm each one passes alignment.
  6. Set a short review point (about two weeks out) to check the first aggregate reports and tighten the policy once everything legitimate is confirmed passing.

In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.

Frequently Asked Questions

What is DMARC and do I actually need it?
DMARC is a DNS record that tells mailbox providers what to do with mail claiming to be from your domain that fails SPF or DKIM. If you send or receive business email on your own domain, it closes a real spoofing gap that SPF and DKIM alone leave open.
What happens if I don't have a DMARC record?
Nothing stops anyone from sending email that looks like it's from your domain to someone else's inbox, and you get no report telling you it's happening. SPF and DKIM failing on their own doesn't block delivery by default.
Will DMARC stop my own emails from being delivered?
Not if it's set up correctly — that's exactly why every sending source gets tested individually before tightening the policy. A rushed or copy-pasted DMARC setup is what causes legitimate mail to start failing, not DMARC itself.
What's the difference between SPF, DKIM and DMARC?
SPF lists which servers are allowed to send for your domain. DKIM adds a cryptographic signature proving a message wasn't altered in transit. DMARC sits on top of both, setting the policy for what happens when either check fails, plus reporting.
Should I set my DMARC policy to reject straight away?
Usually not immediately. Starting at monitoring (p=none) for a couple of weeks shows you every system actually sending on your behalf before anything gets blocked, which avoids accidentally stopping a legitimate tool you forgot about.
Why do Google and Yahoo now require DMARC?
Since February 2024, both require a valid DMARC record (even just p=none) from anyone sending noticeable volumes of mail to their users, as part of a wider push against spoofing and spam. Mail without it can be rejected or sent straight to spam.
How do I read DMARC aggregate reports?
They arrive as XML attachments that are genuinely painful to read by eye — most people use a free parser or dashboard to turn them into a readable list of who's sending as your domain and whether they're passing or failing.
Can DMARC fix emails going to spam?
It can help if spoofing or failed authentication was part of the problem, but DMARC on its own doesn't fix spam placement caused by content, reputation or volume issues — it's one piece of a wider deliverability picture.
Please note: the price shown applies to a standard case matching the description above. Every situation is different, and if your request falls outside the normal scope of this service, I will explain this before doing any additional chargeable work. I will never silently turn a small job into an expensive project.
Running into an issue with a service you've already bought, or unsure which one fits your problem? Message me directly on WhatsApp — no ticket system, no bot.