Skip to main content
Guidance

Email security and anti-spoofing

A guide for IT managers and systems administrators

Page 11 of 14

4. Mark spoof emails as spam

When and how to update your DMARC policy to 'quarantine', and recommendations for keeping everyone in your organisation informed of this change.

You should move to a DMARC policy of ‘quarantine’ as soon as you are confident DKIM and SPF are configured correctly, and all known legitimate sources of email for your domain have been added to your records. Only then will spoof email be hampered.

During the ‘quarantine phase,’ any failed email will be sent to spam/junk (where the recipient has this enabled). This means the messages are recoverable by the recipient.

If you stop feeling confident about your controls, you can revert to the basic DMARC policy of 'none' (and progress again to 'quarantine' when you gain confidence).

Many organisations report being able to move on from a DMARC policy of ‘none’ after about 6 to 8 weeks.

The effect of 'quarantine'

Successfully applying a DMARC policy of 'quarantine' means that emails being sent from your domains, and failing the DKIM and SPF authentication checks, will be sent to the recipient's spam/junk folders.




Published

Reviewed

Version

2.0