Move DMARC from none to quarantine or reject
Increase DMARC enforcement using reports and pct controls.
Objective
Move DMARC toward enforcement
Progress from p=none to quarantine or reject safely.
Starting state
DMARC at p=none with enough aggregate history to trust the sender inventory
Prerequisites
- Clean report history for legitimate senders
- Ability to fix or retire unknown sources
Estimated time
1–2 hours
Difficulty
intermediate
Required access
- DNS
- ESP or MTA admin
Inputs
- Domain
- Target policy (quarantine then reject)
- pct rollout plan
Step-by-step instructions
- Close remaining gapsFix or remove every legitimate source still failing SPF/DKIM alignment in reports.
- Move to quarantine with pctRaise policy to p=quarantine at a low pct, then increase pct as reports stay clean.
- Advance to rejectWhen quarantine is stable, publish p=reject (often with pct ramp) and keep watching rua/ruf.
- Monitor after each changeHold after every policy step long enough to catch false positives before the next increase.
Verification
- Legitimate mail still delivers
- Unauthorized spoof samples are quarantined/rejected as intended
Common mistakes
- Jumping to p=reject with unknown senders still failing
- Ignoring a sudden rua spike after a change
- How long to remain at quarantine before reject?
- Are subdomain policies (sp=) required?
Rollback / recovery
- Lower policy back to p=none or p=quarantine; reduce pct immediately
Expected outcome
DMARC enforcement protects the domain without blocking known-good mail.
When to escalate
- Production mail impacted unexpectedly