Skip to content

Home Topics Email Authentication DMARC

Email Authentication · DMARC

How DMARC policies affects inbox placement

Short answer

DMARC policies affects inbox placement because dMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.

What DMARC policies are#

DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do when a message fails SPF and DKIM alignment, and asks them to send aggregate and forensic reports back to the domain owner.

Why it matters#

DMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.

How mailbox providers use it#

Gmail, Microsoft, and Yahoo combine authentication results, sender reputation, and recipient engagement into a placement decision made per message. DMARC policies feeds directly into that model, and weaknesses compound with other signals.

How to measure the impact#

  1. Baseline inbox placement with seed tests before any change.
  2. Make one change at a time and hold volume steady.
  3. Re-test after 48 to 72 hours; provider models need time to update.
  4. Track Postmaster Tools and SNDS alongside your seed results.

Improving it#

  1. Confirm SPF and DKIM are deployed and aligned for every legitimate sender.
  2. Publish _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com to begin collecting reports.
  3. Analyze aggregate (RUA) reports for 2 to 4 weeks to identify unauthenticated legitimate sources.
  4. Fix each source, then move to p=quarantine with pct=25, ramping to 100.
  5. Move to p=reject and add sp=reject to cover subdomains.
Example DMARC record
_dmarc.example.com.  IN TXT  "v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-rua@example.com; adkim=s; aspf=s; pct=100"

Frequently asked questions#

What is DMARC alignment?

The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.

How long until I can reach p=reject?

Typically 4 to 12 weeks depending on how many third-party senders you have to fix.

What are RUA and RUF reports?

RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.

Analyse your own setup

All analysers
Technical analysis

SPF record analyser

Parse an SPF record, count its DNS lookups, and find what will break it.

Runs in your browser
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser
Technical analysis

DKIM key analyser

Check a DKIM public key's strength, revocation state, and tags.

Runs in your browser

Keep reading on DMARC