DMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.
Mistake 1: Jumping straight to p=reject and blocking your own invoicing or HR system#
Why it hurts: this undermines DMARC policies at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Confirm SPF and DKIM are deployed and aligned for every legitimate sender.
Mistake 2: Sending RUA reports to a mailbox nobody reads; use a report processor#
Why it hurts: this undermines DMARC policies at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Publish _dmarc.yourdomain.com with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com to begin collecting reports.
Mistake 3: Leaving subdomains uncovered because sp= was never set#
Why it hurts: this undermines DMARC policies at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Analyze aggregate (RUA) reports for 2 to 4 weeks to identify unauthenticated legitimate sources.
Mistake 4: Assuming p=none provides protection; it is monitoring only#
Why it hurts: this undermines DMARC policies at the point where mailbox providers make their decision, and it is rarely surfaced by your own tooling until placement drops.
Fix: Fix each source, then move to p=quarantine with pct=25, ramping to 100.
Frequently asked questions#
What is DMARC alignment?
The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.
How long until I can reach p=reject?
Typically 4 to 12 weeks depending on how many third-party senders you have to fix.
What are RUA and RUF reports?
RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.