Help CenterOpen Distro

What is DMARC and how does it work?

DMARC tells receivers what to do when an email fails SPF and DKIM checks for your domain, and sends you reports. Learn how to publish a safe first DMARC record.

Updated 3 min read

DMARC is a DNS record that tells receiving servers what to do with email that claims to be from your domain but fails authentication, and where to send reports about it. It ties SPF and DKIM to the From address people actually see.

How DMARC works

  1. You publish a TXT record at _dmarc.yourdomain.com that starts with v=DMARC1.
  2. When an email arrives showing your domain in the From address, the receiver checks SPF and DKIM.
  3. DMARC passes if at least one of them passes and matches (aligns with) the domain in the From address.
  4. If DMARC fails, the receiver applies your policy and can send you a report.

Alignment is the key idea. An email can pass DKIM with someone else's domain and still fail DMARC for yours. That is why turning on DKIM for your own domain matters.

The three policies

PolicyWhat receivers are asked to do with failing mailWhen to use it
p=noneNothing special, just reportStarting out: you collect reports and learn which services send as you
p=quarantineTreat as suspicious, often the spam folderOnce every legitimate sender passes
p=rejectRefuse the emailFull protection, once you are confident nothing legitimate fails

Start with p=none and move up gradually. Jumping straight to p=reject can block your own legitimate email from a tool you forgot about.

Example record

This is an example of a cautious starting record. Replace the address with a mailbox you control.

Type:  TXT
Host:  _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
  • p=none is the policy.
  • rua= is where aggregate reports go. They arrive as XML files, so many teams use a free or paid DMARC report reader to make sense of them.

What it means for Distro users

  • Google Workspace on your own domain: set up SPF and turn on DKIM for your domain in the Google Admin console first, then publish DMARC. With DKIM signing as your domain, Distro emails sent from your mailbox can pass DMARC.
  • Free @gmail.com address: Google publishes DMARC for gmail.com. You cannot change it.
  • Alias on a different domain: that domain needs its own SPF, DKIM and DMARC. See Send cold email from your custom-domain email.

Google and Yahoo sender requirements

Google and Yahoo publish requirements for people who send email to their users. In general terms they ask all senders to authenticate their mail, and ask higher-volume (bulk) senders to also have SPF, DKIM and a DMARC record, offer easy unsubscribing (including one-click unsubscribe for marketing mail), and keep spam complaint rates low. The exact thresholds and rules change, so check their current guidelines.

Even if you never reach bulk volumes, meeting these requirements is good practice for cold email. Distro's optional Unsubscribe link setting adds a visible link plus the one-click unsubscribe header that Gmail and other mail apps use. It's off by default, so turn it on in each campaign or Compose email where you want it. See Unsubscribes, Do Not Contact, and when to stop.

How to check it

  • Run nslookup -type=txt _dmarc.example.com (Windows) or dig TXT _dmarc.example.com +short (macOS, Linux).
  • Send an email to a Gmail address, open it, choose Show original from the message menu and look for DMARC: PASS.

Common mistakes

  • Publishing at the wrong host. The record lives at _dmarc, not on the root domain.
  • More than one DMARC record. Keep exactly one.
  • Moving to reject too early, before every service that sends as your domain passes.
  • Never reading reports. They show which services send as you and whether they pass.
Still stuck?

Email us at hello@usedistro.com with what you tried and what you see. Signed in? Help & support in the app has walkthrough videos and a message form.

Help & support