How to set up DMARC, step by step

DMARC tells receiving mail servers what to do with email that uses your domain but fails authentication. It only protects you once the policy is quarantine or reject, and rushing there can block your own invoices. Here's the safe order, with records you can copy and where to paste them at common DNS hosts.

By the SBSC Security TeamUpdated 10 min readChanges

In short

  1. Make sure SPF lists every service that sends email as your domain.
  2. Turn on DKIM signing at each of those services.
  3. Publish a DMARC record with p=none and read the reports.
  4. Fix anything legitimate that fails.
  5. Move to p=quarantine, then p=reject.

Before you start

You'll need three things:

  • Access to your DNS host: whoever runs your domain's nameservers, often but not always where you bought the domain. If the lookup below returns names ending in ns.cloudflare.com (like kip.ns.cloudflare.com), add records in Cloudflare (Cloudflare).
  • Admin access to your email service (Google Workspace, Microsoft 365 or similar), to turn on DKIM.
  • A mailbox for reports, such as dmarc-reports@ your domain. Google and Microsoft both recommend a dedicated mailbox or group, not someone's personal inbox.
Command
nslookup -type=NS example.com

Replace example.com with your domain

Then list everything that sends email as your domain: your mailbox provider, website forms, invoicing software, newsletter and CRM tools, booking systems, help desks. Each must pass SPF or DKIM before you enforce DMARC.

Step 1: Get SPF right

SPF is a single TXT record on your domain that lists the servers allowed to send its mail (RFC 7208). Start from your provider's documented record:

TXT recordHost / Name: @
v=spf1 include:_spf.google.com ~all

Google Workspace only (Google's example)

TXT recordHost / Name: @
v=spf1 include:spf.protection.outlook.com -all

Microsoft 365 only (Microsoft's example)

TXT recordHost / Name: @
v=spf1 -all

A domain that never sends email

Three rules trip people up:

  • One SPF record per domain. Two v=spf1 records make SPF fail with a permanent error (RFC 7208, §3.2 and §4.5). Adding a newsletter tool? Add its include: to your existing record instead of creating a second one.
  • Ten DNS lookups at most. Every include, a, mx, ptr, exists and redirect counts, including the ones nested inside includes. Go over ten and SPF fails (RFC 7208 §4.6.4; Microsoft).
  • End with ~all or -all. -all fails mail from anywhere else; ~all accepts it but marks it. The big providers disagree on which is better. Google recommends ~all. Microsoft recommends -all, noting that the DMARC policy is effectively ignored for ~all failures on messages without a DKIM signature, which is one more reason to turn on DKIM in step 2. And RFC 9989 warns that with -all, some receivers reject a message before DMARC runs, even one that would have passed DMARC through DKIM (RFC 9989 §7.1). Our scan accepts either ending once DMARC is enforcing. ?all, +all, or no all at all (without a redirect=) leaves SPF enforcing nothing.

Step 2: Turn on DKIM for every sender

DKIM adds a signature to each message. Receivers check it against a public key you publish at selector._domainkey.yourdomain (RFC 6376 §3.6.2.1).

  • Google Workspace: generate the key in the Admin console and publish it as a TXT record. The default selector is google, so the host is google._domainkey. Then click Start authentication; Google says it can take up to 48 hours to start working (Google).
  • Microsoft 365: add two CNAME records, selector1._domainkey and selector2._domainkey, with the values the Microsoft Defender portal shows for your domain, then turn on signing (Microsoft).
  • Everything else (newsletters, invoicing, CRM): look for a "domain authentication" or DKIM setting. The service gives you the records to add.

Why DKIM if SPF passes? DMARC needs SPF or DKIM to pass for your domain, the one in the visible From address, or by default one of its subdomains. This is called alignment (RFC 9989 §3.2.10). Services that send on your behalf often pass SPF for their domain, so DKIM with your domain is what gets them through (Microsoft). Google recommends setting up SPF and DKIM at least 48 hours before DMARC (Google).

Step 3: Publish DMARC in monitoring mode

Add one TXT record, replacing example.com with your domain:

TXT recordHost / Name: _dmarc
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com

Monitoring only: blocks nothing

TagWhat it does
v=DMARC1Required. Identifies the record.
p=What to do with mail that fails: none (monitor only), quarantine (treat as suspicious, usually the spam folder) or reject. If it's missing, receivers treat it as none.
rua=Where receivers send aggregate reports.
sp=Optional policy for subdomains that exist. Defaults to the p= value.
np=Optional, new in RFC 9989: policy for subdomains that don't exist, such as invoices-2026.example.com when you never created it. Defaults to sp=, then p=.
t=Optional test mode, new in RFC 9989. t=y asks receivers to apply one step less than your policy: reject is treated as quarantine, and quarantine as none. Leave it out (or use t=n) for full enforcement.
pct=Removed in RFC 9989 (it's now listed as historic). Receivers that follow the new standard ignore it; see step 5.

These definitions come from RFC 9989, the current DMARC standard, which replaced RFC 7489 in May 2026 (RFC 9989 §4.7). Existing v=DMARC1 records keep working: the version didn't change.

  • Publish only one record at _dmarc.
  • Reports arrive as XML attachments, usually gzip-compressed, typically covering one day each (RFC 9990). A report viewer helps; if your DNS is on Cloudflare, its DMARC Management feature is available on all plans.
  • If rua points at another company's domain, such as a reporting service, that domain must publish a record authorizing it or receivers won't send reports (RFC 9990 §4). Reporting services handle this.

Not protected yet

p=none blocks nothing. It's a listening period, so you can find every legitimate sender before you enforce.

Step 4: Read the reports and fix your senders

Google suggests starting with p=none for one week and reviewing reports daily; it says a week is usually enough for the reports to cover all your mail streams (Google). If some mail goes out only monthly, such as invoices or newsletters, wait for that too. For each source in the reports:

  • A service you use, passing: nothing to do.
  • A service you use, failing: add it to SPF or turn on DKIM with your domain at that service, then check the next reports.
  • A source you don't recognize, failing: most likely someone sending as you. That's what enforcement will stop.

Step 5: Turn on enforcement

When your legitimate mail passes, tighten the policy. Quarantine asks receivers to treat failing mail as suspicious, usually by delivering it to spam:

TXT recordHost / Name: _dmarc
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com

Enforcement, step one

Reject asks them to refuse it outright:

TXT recordHost / Name: _dmarc
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com

Full enforcement

Google's rollout guide suggests quarantining a small share of mail first with a pct= tag. RFC 9989 removed pct= because receivers applied values other than 0 and 100 inconsistently (RFC 9989, Appendix A.6), so don't count on it. If you want a softer first step, the new t=y tag asks receivers to apply one level less than your policy. Keep rua after you enforce, so a new service that fails shows up in your reports.

For perspective, CISA's Binding Operational Directive 18-01 required U.S. federal agencies to reach p=reject within a year (CISA).

Step 6: Check that it works

Look up the record from a terminal:

Command
nslookup -type=TXT _dmarc.example.com

Replace example.com with your domain

On macOS or Linux, dig +short TXT _dmarc.example.com does the same, and Google's free Admin Toolbox Dig works in a browser. GoDaddy notes that most DNS updates take effect within an hour but can take up to 48 hours.

Then send a message to a Gmail address you own, open it and choose More → Show original (Gmail Help). In the Authentication-Results header you want spf=pass, dkim=pass and dmarc=pass; Microsoft's DMARC guide explains each field.

What our free scan checks: your SPF record (missing, duplicated or broken, and how it ends) and your DMARC record (missing, duplicated, p=none or no p=, test mode, or quarantine rather than reject), graded together: SPF gaps count for less once DMARC is enforcing, +all always counts as High, and ~all is at most a Low note. The $7 report also lists DKIM as a note, since it can't be reliably found without your selector. Run it free.

What "No DMARC record found" and "DMARC policy not enabled" mean

Scanners word these differently; ours calls them "No DMARC record — forged mail is not rejected" and "DMARC is in 'monitor only' mode (p=none)". If SPF is also missing, broken, or ends ?all or with no all, our report folds both into one finding: "Criminals can send email that looks like it's from you".

  • No DMARC record found: nothing valid was found at _dmarc.yourdomain. Usually the record was never added, sits at the wrong name (on the root domain, or at _dmarc.example.com.example.com), or doesn't start with v=DMARC1, in which case receivers must ignore it (RFC 9989 §4.7). A change made in the last day or two may also not have spread yet. Fix it with step 3.
  • DMARC policy not enabled (or "not enforced"): the record exists but is p=none, has no p= (which counts as none), or is p=quarantine with t=y, which receivers apply as none. Fix it with steps 4 and 5.
  • More than one DMARC record: receivers discard them all, so no policy applies (RFC 9989 §4.10). Keep exactly one record at _dmarc.

Where to add the record at common DNS hosts

Add records at your DNS host, which isn't always your registrar (see Before you start). At every host below, the DMARC record is a TXT record whose Host or Name is just _dmarc: the host adds your domain itself. If a saved record reads _dmarc.example.com.example.com, remove the repeated part.

Cloudflare

In the dashboard, open your domain's DNS → Records page and select Add record (Cloudflare). Type TXT, Name _dmarc, Content: your DMARC record. For SPF on the root domain, the Name is @ (Cloudflare).

GoDaddy

In your Domain Portfolio, select the domain, open the DNS tab and select Add New Record. Type TXT, Name _dmarc, Value: your DMARC record; leave TTL at the default and select Save. For SPF on the root domain, the Name is @. GoDaddy says most changes take effect within an hour but can take up to 48 hours (GoDaddy).

Microsoft 365 bought from GoDaddy: GoDaddy's guide has you add SPF and turn on DKIM first, then add the same _dmarc TXT record in GoDaddy's DNS (GoDaddy). DKIM keys are created in Microsoft's Defender portal, not in GoDaddy, and added to GoDaddy's DNS as CNAME records (GoDaddy). GoDaddy's sample record includes pct=100, which RFC 9989 retired; you can leave it out.

Namecheap

Choose Domain List, click Manage next to the domain, open the Advanced DNS tab and click Add New Record. Type TXT Record, Host _dmarc (@ for SPF on the root domain), Value: your record, then save. Namecheap says not to include your domain in the Host field (Namecheap).

Squarespace Domains

Open the domain in your domains dashboard, click DNS, then DNS Settings, scroll to Custom Records and click Add record. Type TXT, Name _dmarc (Squarespace adds your domain automatically); for SPF the Name is @. Squarespace allows only one DMARC record per domain, so if one is already there, edit it instead of adding another (Squarespace).

Wix

Go to Domains, click the Domain Actions icon next to the domain, select Manage DNS Records, and in the TXT section click + Add Record. Host Name _dmarc, Value: your record. Wix says to leave the Host Name blank wherever you'd be told to enter @, as for SPF. If your domain is connected to Wix by pointing rather than by nameservers, add the records at your domain host instead (Wix).

Porkbun

In Domain Management, click DNS under the domain name (or Details, then the edit icon under DNS Records). Type TXT, Host _dmarc, Answer: your record, then click Add. Leave Host blank for the root domain, as for SPF, and don't include your domain in it (Porkbun).

Other hosts

Amazon Route 53: create the record in the domain's hosted zone (AWS). For many other hosts, Microsoft keeps step-by-step instructions for adding DNS records (Microsoft).

The Cloudflare, GoDaddy, Namecheap, Squarespace, Wix and Porkbun steps were last checked against each host's help page on September 28, 2026. Menus change; if yours look different, follow the host's page.

Common questions

Does DMARC stop all email spoofing?

No. Once enforced (p=quarantine or p=reject), it asks receivers to junk or refuse mail that shows your exact domain in the From address without passing aligned SPF or DKIM, and each receiver decides how to apply that. It doesn't cover lookalike domains or fake display names (RFC 9989, section 2.2).

My domain doesn't send email. Do I still need DMARC?

Yes, and it's the easiest case. Publish v=spf1 -all as the domain's SPF record and v=DMARC1; p=reject; at _dmarc. That tells receivers no mail from the domain is legitimate. Microsoft recommends exactly these records for parked domains (SPF, DMARC).

How long should I stay at p=none?

Until your reports show every legitimate sender passing. Google suggests a week; wait longer if you have monthly mail such as invoices.

Is DMARC required?

For bulk senders, yes. Since February 2024 Google has required SPF, DKIM and a DMARC record (p=none is accepted) from senders of more than 5,000 messages a day to Gmail accounts; Yahoo has similar bulk-sender rules, and Microsoft added them for Outlook.com in May 2025. Google requires every sender to use SPF or DKIM. At any volume, an enforced DMARC policy is what lets receivers reject forgeries of your domain.

Sources

  1. IETF — RFC 9989: Domain-Based Message Authentication, Reporting, and Conformance (DMARC), May 2026
  2. IETF — RFC 9990: DMARC Aggregate Reporting, May 2026
  3. IETF — RFC 7208: Sender Policy Framework (SPF)
  4. IETF — RFC 6376: DomainKeys Identified Mail (DKIM) Signatures
  5. Google Workspace Admin Help — Set up SPF
  6. Google Workspace Admin Help — Set up DKIM
  7. Google Workspace Admin Help — Set up DMARC
  8. Google Workspace Admin Help — Recommended DMARC rollout
  9. Microsoft Learn — Set up SPF to identify valid email sources for your Microsoft 365 domain
  10. Microsoft Learn — How to use DKIM for email in your custom domain
  11. Microsoft Learn — Set up DMARC to validate email in Microsoft 365
  12. Google — Email sender guidelines
  13. Yahoo Sender Hub — Sender best practices
  14. Microsoft Tech Community — Outlook's new requirements for high-volume senders (2025)
  15. CISA — BOD 18-01: Enhance Email and Web Security
  16. Cloudflare Docs — Nameservers
  17. Cloudflare Docs — Manage DNS records
  18. Cloudflare Docs — Create zone apex record
  19. Cloudflare Docs — DMARC Management
  20. GoDaddy Help — Add a TXT record
  21. GoDaddy Help — Add a DMARC record to my domain for Microsoft 365
  22. GoDaddy Help — Enable and add DKIM to my domain for Microsoft 365
  23. Namecheap — How do I add TXT/SPF/DKIM/DMARC records for my domain?
  24. Squarespace Help — DNS records for email
  25. Wix Help — Adding or updating TXT records in your Wix account
  26. Porkbun Knowledge Base — How to add DNS records on Porkbun
  27. AWS — Creating records by using the Amazon Route 53 console
  28. Microsoft Learn — Add DNS records to connect your domain
  29. Gmail Help — Trace an email with its full header

Standards and provider settings change. If your provider's current documentation differs from this guide, follow the provider.

Changes to this guide

  • : First published. Host steps checked against each host's help page the same day.

Free security check

See how your site scores, free, in about a minute

We check email spoofing (SPF and DMARC), HTTPS and your certificate, security headers, exposed files, DNS and outdated software. The A–F grade is free; the full report with every fix is a one-time $7.

Passive and read-only. Only scan a domain you own or are authorized to check. Informational, not a guarantee: our scan and guides point out common gaps, not every risk.