What this check looks at
DMARC builds on SPF and DKIM by requiring that at least one of them not only passes but is aligned with the domain in the visible From header. The domain owner publishes a policy at _dmarc.yourdomain.com saying what receivers should do with mail that fails. JoltMx records:
- The DMARC verdict for the message (pass, fail, or a temporary error) and its alignment for SPF and DKIM.
- The policy (
p=none,quarantine, orreject). - Whether the policy applies to all mail or only a sample (
pct). - Whether aggregate reporting (
rua) is configured.
Why it matters
DMARC is what actually stops people spoofing your domain, and Gmail and Yahoo now require it for bulk senders. But it's only protective once it's enforcing: a policy of p=none tells receivers to take no action, so it monitors without defending. The goal is to reach quarantine or reject with confidence that your legitimate mail still aligns.
How the diagnostic grades it
| Result | Severity | What it means |
|---|---|---|
| DMARC passed | Pass | An aligned, passing mechanism satisfied the policy. |
Policy is enforcing (quarantine/reject) | Pass | Spoofed mail is acted on by receivers. |
| DMARC failed | Critical | Neither SPF nor DKIM aligned and passed. Mail is junked or rejected under an enforcing policy. |
| No DMARC record | Warning | No policy published. Start with p=none plus a rua address. |
Policy is monitor-only (p=none) | Info | Right starting point, but no protection yet. Move to enforcement. |
Applies to a sample only (pct<100) | Info | Fine during migration; remove pct once confident. |
No aggregate reporting (rua) | Info | You get no reports on who sends as your domain. Add rua=mailto:. |
| Temporary error | Info | DNS was briefly unavailable. Re-test. |
How to fix it
Publish a record and tighten it as your confidence grows:
Type Host Value
TXT _dmarc v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
- Start at
p=noneand read the aggregate reports until your real mail passes cleanly. - Move to
p=quarantine, thenp=rejectfor full protection. - If DMARC is failing, the cause is almost always alignment - fix that before touching the policy.
Forwarded mail can fail DMARC even when the original was perfect. See ARC and message type for why, and what to do about it.
Related checks
SPF · DKIM · From alignment · Policy disposition · SPF, DKIM & DMARC explained