What is DMARC and how does it work?
DMARC tells receivers what to do when an email fails SPF and DKIM checks for your domain, and sends you reports. Learn how to publish a safe first DMARC record.
DMARC is a DNS record that tells receiving servers what to do with email that claims to be from your domain but fails authentication, and where to send reports about it. It ties SPF and DKIM to the From address people actually see.
How DMARC works
- You publish a TXT record at
_dmarc.yourdomain.comthat starts withv=DMARC1. - When an email arrives showing your domain in the From address, the receiver checks SPF and DKIM.
- DMARC passes if at least one of them passes and matches (aligns with) the domain in the From address.
- If DMARC fails, the receiver applies your policy and can send you a report.
Alignment is the key idea. An email can pass DKIM with someone else's domain and still fail DMARC for yours. That is why turning on DKIM for your own domain matters.
The three policies
| Policy | What receivers are asked to do with failing mail | When to use it |
|---|---|---|
p=none | Nothing special, just report | Starting out: you collect reports and learn which services send as you |
p=quarantine | Treat as suspicious, often the spam folder | Once every legitimate sender passes |
p=reject | Refuse the email | Full protection, once you are confident nothing legitimate fails |
Start with p=none and move up gradually. Jumping straight to p=reject can block your own legitimate email from a tool you forgot about.
Example record
This is an example of a cautious starting record. Replace the address with a mailbox you control.
Type: TXT
Host: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.comp=noneis the policy.rua=is where aggregate reports go. They arrive as XML files, so many teams use a free or paid DMARC report reader to make sense of them.
What it means for Distro users
- Google Workspace on your own domain: set up SPF and turn on DKIM for your domain in the Google Admin console first, then publish DMARC. With DKIM signing as your domain, Distro emails sent from your mailbox can pass DMARC.
- Free @gmail.com address: Google publishes DMARC for gmail.com. You cannot change it.
- Alias on a different domain: that domain needs its own SPF, DKIM and DMARC. See Send cold email from your custom-domain email.
Google and Yahoo sender requirements
Google and Yahoo publish requirements for people who send email to their users. In general terms they ask all senders to authenticate their mail, and ask higher-volume (bulk) senders to also have SPF, DKIM and a DMARC record, offer easy unsubscribing (including one-click unsubscribe for marketing mail), and keep spam complaint rates low. The exact thresholds and rules change, so check their current guidelines.
Even if you never reach bulk volumes, meeting these requirements is good practice for cold email. Distro's optional Unsubscribe link setting adds a visible link plus the one-click unsubscribe header that Gmail and other mail apps use. It's off by default, so turn it on in each campaign or Compose email where you want it. See Unsubscribes, Do Not Contact, and when to stop.
How to check it
- Run
nslookup -type=txt _dmarc.example.com(Windows) ordig TXT _dmarc.example.com +short(macOS, Linux). - Send an email to a Gmail address, open it, choose Show original from the message menu and look for DMARC: PASS.
Common mistakes
- Publishing at the wrong host. The record lives at
_dmarc, not on the root domain. - More than one DMARC record. Keep exactly one.
- Moving to
rejecttoo early, before every service that sends as your domain passes. - Never reading reports. They show which services send as you and whether they pass.
Email us at hello@usedistro.com with what you tried and what you see. Signed in? Help & support in the app has walkthrough videos and a message form.