What Spam Act 2003 requires#
The Spam Act requires consent, sender identification, and a functional unsubscribe in every commercial message.
What DMARC policies are#
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do when a message fails SPF and DKIM alignment, and asks them to send aggregate and forensic reports back to the domain owner.
Why it matters#
DMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.
How DMARC policies supports Spam Act 2003 compliance#
Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. DMARC policies contributes by dMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.
Implementation steps#
- Confirm SPF and DKIM are deployed and aligned for every legitimate sender.
- Publish _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com to begin collecting reports.
- Analyze aggregate (RUA) reports for 2 to 4 weeks to identify unauthenticated legitimate sources.
- Fix each source, then move to p=quarantine with pct=25, ramping to 100.
- Move to p=reject and add sp=reject to cover subdomains.
_dmarc.example.com. IN TXT "v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-rua@example.com; adkim=s; aspf=s; pct=100"Frequently asked questions#
What is DMARC alignment?
The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.
How long until I can reach p=reject?
Typically 4 to 12 weeks depending on how many third-party senders you have to fix.
What are RUA and RUF reports?
RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.