Terms below appear throughout guides on DMARC policies. Each definition is one or two sentences; follow the links in the sidebar for the full guides.
Core terms#
DMARC policies
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do when a message fails SPF and DKIM alignment, and asks them to send aggregate and forensic reports back to the domain owner.
SPF
A DNS record listing servers authorized to send for a domain. Checked against the connecting IP.
DKIM
A cryptographic signature on each message, verified with a public key in DNS.
DMARC
A policy record telling receivers what to do when SPF and DKIM fail alignment, plus reporting.
Alignment
Agreement between the visible From domain and the domain that passed SPF or DKIM.
Sender reputation
A provider's running assessment of a domain or IP based on complaints, bounces, engagement, and authentication.
Inbox placement
Share of accepted mail that lands in the inbox rather than spam.
Spam trap
An address that never opted in, used to catch senders with poor list practices.
BIMI
A DNS record pointing to a brand logo displayed next to authenticated mail; requires DMARC enforcement.
Feedback loop
A provider program that reports recipient spam complaints back to the sender.
Frequently asked questions#
What is DMARC alignment?
The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.
How long until I can reach p=reject?
Typically 4 to 12 weeks depending on how many third-party senders you have to fix.
What are RUA and RUF reports?
RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.