Skip to main content
← Back to glossary
Email deliverability

DMARC — Domain-based Message Authentication, Reporting & Conformance

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting & Conformance) is the email standard that tells receiving mail servers what to do with a message that fails SPF or DKIM authentication — quarantine it, reject it, or let it through — and sends the domain owner reports on authentication failures across the internet. DMARC is what actually enforces SPF and DKIM: without a DMARC policy, a receiving server may still deliver an unauthenticated message that merely fails those underlying checks.

More detail

A DMARC policy is published as a DNS record and typically starts at a monitor-only setting (collecting reports without blocking anything) before a domain owner tightens it to quarantine or reject once they've confirmed legitimate mail isn't being caught.

DMARC reports reveal exactly which servers are sending mail claiming to be from a domain, including spoofing or phishing attempts, which is why DMARC is as much an anti-phishing tool as a deliverability one.

Frequently asked

Do I need SPF and DKIM if I already have DMARC?
Yes — DMARC doesn't replace SPF and DKIM, it enforces them: a DMARC policy tells receiving servers what to do based on whether a message passes those underlying checks, so all three work together rather than DMARC standing alone.
Why start a DMARC policy at monitor-only instead of reject?
Starting at monitor-only lets a domain owner see authentication reports and confirm every legitimate sending source is properly configured before tightening to quarantine or reject, avoiding accidentally blocking real mail during the rollout.

Build it on Orbit

Voice, messaging, email, video, and AI agents on one platform and one pay-as-you-go bill. Start free — no credit card required.