Skip to main content
Guidance

Email security and anti-spoofing

A guide for IT managers and systems administrators

Page 12 of 14

5. Reject spoof emails

When and how to update your DMARC policy to 'reject', and recommendations for keeping everyone in your organisation informed and monitoring your records.

At this point you should have identified and resolved any issues arising during the “quarantine phase”. As soon as you are confident DKIM and SPF are continuing to work correctly, you should move to a DMARC policy of ‘reject’

Having a DMARC policy of ‘reject’ on all of your domains is the best way to prevent spoofing of your email. The goal for this section is to help you get to that point.

Many organisations report being able to move on from a DMARC policy of ‘quarantine’ to one of 'reject' after about 3 months.


Reject and quarantine

If you have pct=50 in your reject record, a policy of quarantine will be applied to all remaining email. 



Published

Reviewed

Version

2.0