DMARC check

DMARC is the policy that ties SPF and DKIM together and tells receivers what to do when they fail. This check grades the verdict for your message and analyses the published policy.

What this check looks at

DMARC builds on SPF and DKIM by requiring that at least one of them not only passes but is aligned with the domain in the visible From header. The domain owner publishes a policy at _dmarc.yourdomain.com saying what receivers should do with mail that fails. JoltMx records:

  • The DMARC verdict for the message (pass, fail, or a temporary error) and its alignment for SPF and DKIM.
  • The policy (p=none, quarantine, or reject).
  • Whether the policy applies to all mail or only a sample (pct).
  • Whether aggregate reporting (rua) is configured.

Why it matters

DMARC is what actually stops people spoofing your domain, and Gmail and Yahoo now require it for bulk senders. But it's only protective once it's enforcing: a policy of p=none tells receivers to take no action, so it monitors without defending. The goal is to reach quarantine or reject with confidence that your legitimate mail still aligns.

How the diagnostic grades it

ResultSeverityWhat it means
DMARC passedPassAn aligned, passing mechanism satisfied the policy.
Policy is enforcing (quarantine/reject)PassSpoofed mail is acted on by receivers.
DMARC failedCriticalNeither SPF nor DKIM aligned and passed. Mail is junked or rejected under an enforcing policy.
No DMARC recordWarningNo policy published. Start with p=none plus a rua address.
Policy is monitor-only (p=none)InfoRight starting point, but no protection yet. Move to enforcement.
Applies to a sample only (pct<100)InfoFine during migration; remove pct once confident.
No aggregate reporting (rua)InfoYou get no reports on who sends as your domain. Add rua=mailto:.
Temporary errorInfoDNS was briefly unavailable. Re-test.

How to fix it

Publish a record and tighten it as your confidence grows:

Type   Host      Value
TXT    _dmarc    v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
  • Start at p=none and read the aggregate reports until your real mail passes cleanly.
  • Move to p=quarantine, then p=reject for full protection.
  • If DMARC is failing, the cause is almost always alignment - fix that before touching the policy.
Forwarded mail can fail DMARC even when the original was perfect. See ARC and message type for why, and what to do about it.

Related checks

SPF · DKIM · From alignment · Policy disposition · SPF, DKIM & DMARC explained

Free during beta

Start routing mail in minutes.

Point your MX records at JoltMx. Add a domain. Create your first rule. Done.

No credit card required  ·  Free tier stays free