/ developer & network toolbox
← all tools

$ dmarc p=

runs locally

DMARC Policy: none, quarantine or reject

Pick the right DMARC policy and build the record: what p=none, p=quarantine and p=reject do, and how to move between them safely.

dmarc-policy — invoker.tools
typeTXT
host_dmarc
v=DMARC1; p=none
v=DMARC1Identifies the record as DMARC. Must come first.
p=noneMonitor only: failing mail is delivered as normal, you just receive reports.
⚠ p=none does not stop spoofing. Use it to collect reports first, then move to quarantine and reject.
⚠ No rua address: you will not see who sends mail as your domain, which makes tightening the policy guesswork.

About the DMARC Policy: none, quarantine or reject

The p tag is the heart of a DMARC record: it tells receiving mail servers what to do with a message that claims to be from your domain but is not backed by an aligned SPF or DKIM pass. There are three options. p=none takes no action and only collects reports. p=quarantine asks receivers to treat failing mail as suspicious, which in practice means the spam or junk folder. p=reject asks them to refuse failing mail during the SMTP conversation, so it never reaches the recipient at all. The generator above builds the record for whichever policy you pick and explains each tag.

Only quarantine and reject actually protect a domain against spoofing. p=none is a monitoring mode: useful and even required as a first step, but a domain that stays on none indefinitely can still be impersonated in phishing mail. Since 2024, Google and Yahoo require bulk senders to publish at least p=none, which pushed many domains to add DMARC without ever finishing the rollout.

The safe path is to start with none and a rua address, read the aggregate reports until every legitimate sender passes with alignment, and then tighten the policy step by step. Skipping straight to reject without that inventory is how organisations end up blocking their own invoices, newsletters or helpdesk replies.

How to use it

  1. Pick the policy that matches where the domain is in its rollout: none for a new setup, quarantine once reports look clean, reject as the end goal.
  2. Always add a rua address so you keep seeing what fails after you tighten the policy.
  3. Use pct to take quarantine or reject in steps if the domain sends from many sources.
  4. Set sp=reject if subdomains never send mail, even while the main domain is still on none or quarantine.
  5. Copy the record, replace the TXT record at _dmarc, and verify it with the DMARC checker.

Examples

  • v=DMARC1; p=none; rua=mailto:dmarc@example.com: collect reports, no effect on delivery.
  • v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@example.com: a quarter of failing mail to spam.
  • v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com: all failing mail to spam.
  • v=DMARC1; p=reject; rua=mailto:dmarc@example.com: failing mail refused, full spoofing protection.
  • v=DMARC1; p=reject; sp=reject: a domain that sends no mail at all (combine with v=spf1 -all).

The three policies compared

  • p=none: no action on failing mail, reports only. Protection: none. Risk to legitimate mail: none.
  • p=quarantine: failing mail goes to spam or quarantine. Protection: good, phishing lands in junk. Risk: missed senders end up in spam, where they can still be found.
  • p=reject: failing mail is refused. Protection: strongest, spoofed mail never arrives. Risk: missed senders bounce, so finish the inventory first.

How to move from none to reject safely

  • Publish p=none with a rua address and wait at least two to four weeks of reports.
  • List every source in the reports: your mailbox provider, marketing, CRM, invoicing, helpdesk, website forms.
  • Make each legitimate source pass with alignment, preferably by DKIM signing with your domain.
  • Switch to p=quarantine, optionally with a low pct, and keep reading reports.
  • Move to p=reject once quarantine has run without legitimate failures.

Domains that do not send mail

Parked domains and domains used only for a website are popular for spoofing precisely because nobody watches them. For those, publish p=reject straight away, together with v=spf1 -all and no DKIM keys. There are no legitimate senders to break, so there is no reason to go through a monitoring phase.

Frequently asked questions

What is the difference between p=quarantine and p=reject?

Quarantine delivers failing mail to the spam folder; reject refuses it so it never arrives. Reject protects better, quarantine is more forgiving if a legitimate sender was missed.

Does p=none protect my domain?

No. It only produces reports. Spoofed mail is still delivered normally, so none should be a temporary phase.

Is p=reject bad for deliverability?

Not for mail that passes DMARC. It only affects messages that fail, which are either spoofed or sent by a service you have not set up correctly yet.

Do mailing lists break with p=reject?

Older list software that modifies messages can break DKIM and trigger rejections. Most modern list servers rewrite the From address for DMARC-protected domains to avoid this.

How quickly does a policy change take effect?

As soon as the TXT record's TTL has expired at the receiver's resolver, usually within minutes to an hour.

More email / dns tools