Email security and anti-spoofing
Pages
Page 7 of 14
Implement a DMARC policy of ‘none’
Understand how to create the DMARC record for all of your domains, and see our recommendation for how to apply DMARC effectively and safely.
All of your domains, including parked domains, should have DMARC records in place, regardless of whether the domain is used for email or not.
We recommend you apply DMARC gradually, iterating your DMARC configuration over time.
Start by implementing a DMARC policy of ‘none’. You can view this policy as a ‘monitoring phase’, during which the DMARC processing tool you selected in Step 1 collects and reports on which systems and services are sending emails from your domains. This does not interfere with your email traffic in any way.
The list of email senders collected by your processing tool during this stage will probably include your legitimate internal email users and any third parties you use for things like marketing email campaigns. It will also include any sources which are spoofing your domain.
Take your time
A DMARC policy of 'none' will give you time to understand whether you have configured DKIM and SPF correctly.
How to create the DMARC record
Note
In this example, we have used yourdomain.gov.uk. You should replace yourdomain.gov.uk with your actual domain (which can be .gov.uk, .com etc.).
Update your public DNS record as detailed below.
Your DMARC record name is:
_dmarc.yourdomain.gov.uk
It should be configured as a TXT record, with an initial value similar to this:
v=DMARC1;p=none;rua=mailto:[email protected]
The 'p=none' part of the record above specifies the requested policy that mail receivers should apply. A policy of 'none' means this DMARC record won’t affect the delivery of your email, but it will provide you with reports on where your outbound email appears to be coming from.
The email address in the record should be provided by the DMARC processing tool you've chosen (noting that [email protected] shown above is fictional). If the tool does not provide one, it should be a mailbox you have chosen or created for this purpose.
“rua” is a comma separated list of URI(s) for aggregate report delivery. This report contains details of the emails being sent from your domain, including whether they passed or failed the SPF and DKIM authentication checks. You can include up to 2 email addresses for which to send the aggregated data reports. If you’re eligible to use Mail Check and do, you need to include our email address, to ensure that you send the aggregated data to Mail Check - details are provided within Mail Check.
Note
In this ‘monitoring only phase’ we recommend keeping your DMARC record as simple as shown above. You do not need to add additional ‘DMARC tags’ (see https://tools.ietf.org/html/rfc7489#page-17) at this stage.
Semi-colons are used to separate the tags. Commas are used to separate multiple email addresses (where more than one is used).
You do not need a semi-colon (or full stop) at the end of the DMARC record.
DMARC Reports
Within 24 hours of publishing your records you’ll start receiving email reports from major email recipient domains. These will come to the two addresses you specified in your DMARC record.
The information in the reports will show
- Where the outgoing email from your domains originates.
- How it's being handled by the major recipients. In other words, whether it has passed or failed the DKIM and SPF checks undertaken by the recipient.


