How to set up DMARC, step by step
DMARC tells receiving mail servers what to do with email that uses your domain but fails authentication. It only protects you once the policy is quarantine or reject, and rushing there can block your own invoices. Here's the safe order, with records you can copy and where to paste them at common DNS hosts.
In short
- Make sure SPF lists every service that sends email as your domain.
- Turn on DKIM signing at each of those services.
- Publish a DMARC record with
p=noneand read the reports. - Fix anything legitimate that fails.
- Move to
p=quarantine, thenp=reject.
Before you start
You'll need three things:
- Access to your DNS host: whoever runs your domain's nameservers, often but not always where you bought the domain. If the lookup below returns names ending in
ns.cloudflare.com(likekip.ns.cloudflare.com), add records in Cloudflare (Cloudflare). - Admin access to your email service (Google Workspace, Microsoft 365 or similar), to turn on DKIM.
- A mailbox for reports, such as
dmarc-reports@your domain. Google and Microsoft both recommend a dedicated mailbox or group, not someone's personal inbox.
nslookup -type=NS example.com
Replace example.com with your domain
Then list everything that sends email as your domain: your mailbox provider, website forms, invoicing software, newsletter and CRM tools, booking systems, help desks. Each must pass SPF or DKIM before you enforce DMARC.
Step 1: Get SPF right
SPF is a single TXT record on your domain that lists the servers allowed to send its mail (RFC 7208). Start from your provider's documented record:
@v=spf1 include:_spf.google.com ~all
Google Workspace only (Google's example)
@v=spf1 include:spf.protection.outlook.com -all
Microsoft 365 only (Microsoft's example)
@v=spf1 -all
A domain that never sends email
Three rules trip people up:
- One SPF record per domain. Two
v=spf1records make SPF fail with a permanent error (RFC 7208, §3.2 and §4.5). Adding a newsletter tool? Add itsinclude:to your existing record instead of creating a second one. - Ten DNS lookups at most. Every
include,a,mx,ptr,existsandredirectcounts, including the ones nested inside includes. Go over ten and SPF fails (RFC 7208 §4.6.4; Microsoft). - End with
~allor-all.-allfails mail from anywhere else;~allaccepts it but marks it. The big providers disagree on which is better. Google recommends~all. Microsoft recommends-all, noting that the DMARC policy is effectively ignored for~allfailures on messages without a DKIM signature, which is one more reason to turn on DKIM in step 2. And RFC 9989 warns that with-all, some receivers reject a message before DMARC runs, even one that would have passed DMARC through DKIM (RFC 9989 §7.1). Our scan accepts either ending once DMARC is enforcing.?all,+all, or noallat all (without aredirect=) leaves SPF enforcing nothing.
Step 2: Turn on DKIM for every sender
DKIM adds a signature to each message. Receivers check it against a public key you publish at selector._domainkey.yourdomain (RFC 6376 §3.6.2.1).
- Google Workspace: generate the key in the Admin console and publish it as a TXT record. The default selector is
google, so the host isgoogle._domainkey. Then click Start authentication; Google says it can take up to 48 hours to start working (Google). - Microsoft 365: add two CNAME records,
selector1._domainkeyandselector2._domainkey, with the values the Microsoft Defender portal shows for your domain, then turn on signing (Microsoft). - Everything else (newsletters, invoicing, CRM): look for a "domain authentication" or DKIM setting. The service gives you the records to add.
Why DKIM if SPF passes? DMARC needs SPF or DKIM to pass for your domain, the one in the visible From address, or by default one of its subdomains. This is called alignment (RFC 9989 §3.2.10). Services that send on your behalf often pass SPF for their domain, so DKIM with your domain is what gets them through (Microsoft). Google recommends setting up SPF and DKIM at least 48 hours before DMARC (Google).
Step 3: Publish DMARC in monitoring mode
Add one TXT record, replacing example.com with your domain:
_dmarcv=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
Monitoring only: blocks nothing
| Tag | What it does |
|---|---|
v=DMARC1 | Required. Identifies the record. |
p= | What to do with mail that fails: none (monitor only), quarantine (treat as suspicious, usually the spam folder) or reject. If it's missing, receivers treat it as none. |
rua= | Where receivers send aggregate reports. |
sp= | Optional policy for subdomains that exist. Defaults to the p= value. |
np= | Optional, new in RFC 9989: policy for subdomains that don't exist, such as invoices-2026.example.com when you never created it. Defaults to sp=, then p=. |
t= | Optional test mode, new in RFC 9989. t=y asks receivers to apply one step less than your policy: reject is treated as quarantine, and quarantine as none. Leave it out (or use t=n) for full enforcement. |
pct= | Removed in RFC 9989 (it's now listed as historic). Receivers that follow the new standard ignore it; see step 5. |
These definitions come from RFC 9989, the current DMARC standard, which replaced RFC 7489 in May 2026 (RFC 9989 §4.7). Existing v=DMARC1 records keep working: the version didn't change.
- Publish only one record at
_dmarc. - Reports arrive as XML attachments, usually gzip-compressed, typically covering one day each (RFC 9990). A report viewer helps; if your DNS is on Cloudflare, its DMARC Management feature is available on all plans.
- If
ruapoints at another company's domain, such as a reporting service, that domain must publish a record authorizing it or receivers won't send reports (RFC 9990 §4). Reporting services handle this.
Not protected yet
p=none blocks nothing. It's a listening period, so you can find every legitimate sender before you enforce.
Step 4: Read the reports and fix your senders
Google suggests starting with p=none for one week and reviewing reports daily; it says a week is usually enough for the reports to cover all your mail streams (Google). If some mail goes out only monthly, such as invoices or newsletters, wait for that too. For each source in the reports:
- A service you use, passing: nothing to do.
- A service you use, failing: add it to SPF or turn on DKIM with your domain at that service, then check the next reports.
- A source you don't recognize, failing: most likely someone sending as you. That's what enforcement will stop.
Step 5: Turn on enforcement
When your legitimate mail passes, tighten the policy. Quarantine asks receivers to treat failing mail as suspicious, usually by delivering it to spam:
_dmarcv=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com
Enforcement, step one
Reject asks them to refuse it outright:
_dmarcv=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com
Full enforcement
Google's rollout guide suggests quarantining a small share of mail first with a pct= tag. RFC 9989 removed pct= because receivers applied values other than 0 and 100 inconsistently (RFC 9989, Appendix A.6), so don't count on it. If you want a softer first step, the new t=y tag asks receivers to apply one level less than your policy. Keep rua after you enforce, so a new service that fails shows up in your reports.
For perspective, CISA's Binding Operational Directive 18-01 required U.S. federal agencies to reach p=reject within a year (CISA).
Step 6: Check that it works
Look up the record from a terminal:
nslookup -type=TXT _dmarc.example.com
Replace example.com with your domain
On macOS or Linux, dig +short TXT _dmarc.example.com does the same, and Google's free Admin Toolbox Dig works in a browser. GoDaddy notes that most DNS updates take effect within an hour but can take up to 48 hours.
Then send a message to a Gmail address you own, open it and choose More → Show original (Gmail Help). In the Authentication-Results header you want spf=pass, dkim=pass and dmarc=pass; Microsoft's DMARC guide explains each field.
What our free scan checks: your SPF record (missing, duplicated or broken, and how it ends) and your DMARC record (missing, duplicated, p=none or no p=, test mode, or quarantine rather than reject), graded together: SPF gaps count for less once DMARC is enforcing, +all always counts as High, and ~all is at most a Low note. The $7 report also lists DKIM as a note, since it can't be reliably found without your selector. Run it free.
What "No DMARC record found" and "DMARC policy not enabled" mean
Scanners word these differently; ours calls them "No DMARC record — forged mail is not rejected" and "DMARC is in 'monitor only' mode (p=none)". If SPF is also missing, broken, or ends ?all or with no all, our report folds both into one finding: "Criminals can send email that looks like it's from you".
- No DMARC record found: nothing valid was found at
_dmarc.yourdomain. Usually the record was never added, sits at the wrong name (on the root domain, or at_dmarc.example.com.example.com), or doesn't start withv=DMARC1, in which case receivers must ignore it (RFC 9989 §4.7). A change made in the last day or two may also not have spread yet. Fix it with step 3. - DMARC policy not enabled (or "not enforced"): the record exists but is
p=none, has nop=(which counts asnone), or isp=quarantinewitht=y, which receivers apply asnone. Fix it with steps 4 and 5. - More than one DMARC record: receivers discard them all, so no policy applies (RFC 9989 §4.10). Keep exactly one record at
_dmarc.
Where to add the record at common DNS hosts
Add records at your DNS host, which isn't always your registrar (see Before you start). At every host below, the DMARC record is a TXT record whose Host or Name is just _dmarc: the host adds your domain itself. If a saved record reads _dmarc.example.com.example.com, remove the repeated part.
Cloudflare
In the dashboard, open your domain's DNS → Records page and select Add record (Cloudflare). Type TXT, Name _dmarc, Content: your DMARC record. For SPF on the root domain, the Name is @ (Cloudflare).
GoDaddy
In your Domain Portfolio, select the domain, open the DNS tab and select Add New Record. Type TXT, Name _dmarc, Value: your DMARC record; leave TTL at the default and select Save. For SPF on the root domain, the Name is @. GoDaddy says most changes take effect within an hour but can take up to 48 hours (GoDaddy).
Microsoft 365 bought from GoDaddy: GoDaddy's guide has you add SPF and turn on DKIM first, then add the same _dmarc TXT record in GoDaddy's DNS (GoDaddy). DKIM keys are created in Microsoft's Defender portal, not in GoDaddy, and added to GoDaddy's DNS as CNAME records (GoDaddy). GoDaddy's sample record includes pct=100, which RFC 9989 retired; you can leave it out.
Namecheap
Choose Domain List, click Manage next to the domain, open the Advanced DNS tab and click Add New Record. Type TXT Record, Host _dmarc (@ for SPF on the root domain), Value: your record, then save. Namecheap says not to include your domain in the Host field (Namecheap).
Squarespace Domains
Open the domain in your domains dashboard, click DNS, then DNS Settings, scroll to Custom Records and click Add record. Type TXT, Name _dmarc (Squarespace adds your domain automatically); for SPF the Name is @. Squarespace allows only one DMARC record per domain, so if one is already there, edit it instead of adding another (Squarespace).
Wix
Go to Domains, click the Domain Actions icon next to the domain, select Manage DNS Records, and in the TXT section click + Add Record. Host Name _dmarc, Value: your record. Wix says to leave the Host Name blank wherever you'd be told to enter @, as for SPF. If your domain is connected to Wix by pointing rather than by nameservers, add the records at your domain host instead (Wix).
Porkbun
In Domain Management, click DNS under the domain name (or Details, then the edit icon under DNS Records). Type TXT, Host _dmarc, Answer: your record, then click Add. Leave Host blank for the root domain, as for SPF, and don't include your domain in it (Porkbun).
Other hosts
Amazon Route 53: create the record in the domain's hosted zone (AWS). For many other hosts, Microsoft keeps step-by-step instructions for adding DNS records (Microsoft).
The Cloudflare, GoDaddy, Namecheap, Squarespace, Wix and Porkbun steps were last checked against each host's help page on September 28, 2026. Menus change; if yours look different, follow the host's page.
Common questions
Does DMARC stop all email spoofing?
No. Once enforced (p=quarantine or p=reject), it asks receivers to junk or refuse mail that shows your exact domain in the From address without passing aligned SPF or DKIM, and each receiver decides how to apply that. It doesn't cover lookalike domains or fake display names (RFC 9989, section 2.2).
My domain doesn't send email. Do I still need DMARC?
How long should I stay at p=none?
Until your reports show every legitimate sender passing. Google suggests a week; wait longer if you have monthly mail such as invoices.
Is DMARC required?
For bulk senders, yes. Since February 2024 Google has required SPF, DKIM and a DMARC record (p=none is accepted) from senders of more than 5,000 messages a day to Gmail accounts; Yahoo has similar bulk-sender rules, and Microsoft added them for Outlook.com in May 2025. Google requires every sender to use SPF or DKIM. At any volume, an enforced DMARC policy is what lets receivers reject forgeries of your domain.
Sources
- IETF — RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC), May 2026
- IETF — RFC 9990: DMARC Aggregate Reporting, May 2026
- IETF — RFC 7208: Sender Policy Framework (SPF)
- IETF — RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
- Google Workspace Admin Help — Set up SPF
- Google Workspace Admin Help — Set up DKIM
- Google Workspace Admin Help — Set up DMARC
- Google Workspace Admin Help — Recommended DMARC rollout
- Microsoft Learn — Set up SPF to identify valid email sources for your Microsoft 365 domain
- Microsoft Learn — How to use DKIM for email in your custom domain
- Microsoft Learn — Set up DMARC to validate email in Microsoft 365
- Google — Email sender guidelines
- Yahoo Sender Hub — Sender best practices
- Microsoft Tech Community — Outlook's new requirements for high-volume senders (2025)
- CISA — BOD 18-01: Enhance Email and Web Security
- Cloudflare Docs — Nameservers
- Cloudflare Docs — Manage DNS records
- Cloudflare Docs — Create zone apex record
- Cloudflare Docs — DMARC Management
- GoDaddy Help — Add a TXT record
- GoDaddy Help — Add a DMARC record to my domain for Microsoft 365
- GoDaddy Help — Enable and add DKIM to my domain for Microsoft 365
- Namecheap — How do I add TXT/SPF/DKIM/DMARC records for my domain?
- Squarespace Help — DNS records for email
- Wix Help — Adding or updating TXT records in your Wix account
- Porkbun Knowledge Base — How to add DNS records on Porkbun
- AWS — Creating records by using the Amazon Route 53 console
- Microsoft Learn — Add DNS records to connect your domain
- Gmail Help — Trace an email with its full header
Standards and provider settings change. If your provider's current documentation differs from this guide, follow the provider.
Changes to this guide
- : First published. Host steps checked against each host's help page the same day.