SPF and DKIM authenticate; DMARC adds policy and reporting on top. You cannot enforce DMARC without at least one of them aligned.
What DMARC policies are#
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do when a message fails SPF and DKIM alignment, and asks them to send aggregate and forensic reports back to the domain owner.
Why it matters#
DMARC at p=reject is what actually stops exact-domain spoofing. Gmail and Yahoo require at least p=none for bulk senders, and BIMI requires p=quarantine or p=reject.
How SPF and DKIM differs#
SPF and DKIM solves an adjacent problem. SPF and DKIM authenticate; DMARC adds policy and reporting on top. You cannot enforce DMARC without at least one of them aligned. In practice the two are deployed together and monitored with the same reporting.
Which to implement first#
Start with whichever your sending platform makes easiest, then add the other. Deployment order matters less than reaching a state where both pass and align with your From domain.
Frequently asked questions#
What is DMARC alignment?
The domain in the visible From header must match (exactly or organizationally) the domain that passed SPF or DKIM. Set adkim=s and aspf=s for strict matching.
How long until I can reach p=reject?
Typically 4 to 12 weeks depending on how many third-party senders you have to fix.
What are RUA and RUF reports?
RUA are daily aggregate XML reports of pass/fail counts per source. RUF are per-message forensic samples; many receivers no longer send them.