Why DMARC is worth having before anything goes wrong
Email was designed so that the From line is just text. Anyone, anywhere, can send a message that says it is from your domain, and nothing in the protocol stops them. SPF and DKIM exist to prove where mail really came from — but on their own they carry no instruction, and a receiver that sees them fail is left to guess. DMARC is the missing piece: a DNS record that ties those checks to the visible From address and tells every major receiver, in advance, what to do when a message claiming your name fails them.
What you get on day one
The first thing DMARC gives you is not protection — it is sight. A record with
p=none changes nothing about delivery; it simply asks receivers to send you
daily aggregate reports: which servers sent mail as your domain, how much, and whether it
authenticated. Gmail, Microsoft, Yahoo and most large receivers honour it. Until you
publish that request, those reports do not exist — there is no log to go back and read on
the day you first need one.
Most domain owners are surprised by their own reports. A billing tool somebody signed up for years ago, a newsletter platform, a web server that sends password resets — and, often enough, senders that are nobody's: addresses on other continents putting your name on messages you never sent.
What it costs you to not have it
- Somebody else's fraud wears your name. Invoice fraud and phishing almost always borrow a real domain, and a domain with no DMARC policy is the easy choice: receivers have no instruction to refuse the forgery, so it lands. The people it lands on are your customers and suppliers — the ones most likely to trust the name.
- Your own mail becomes second-class. Since 2024 the large mailbox providers require DMARC from bulk senders outright, and mail from unauthenticated domains is increasingly filtered on suspicion. The record is no longer optional hygiene; it is part of what "deliverable" means.
- You find out late, or never. Without reports, the first sign your domain is being spoofed is usually a confused reply, a partner's warning — or nothing at all while it keeps happening.
The ladder, and why it is a ladder
DMARC has three policies, and they are meant to be climbed in order — for a domain that sends mail, each step is a promise that your own messages will survive it.
p=none— monitor only. Reports flow, delivery is untouched. The right place to start; the wrong place to stay.p=quarantine— mail that fails goes to spam folders. Reversible, and the first policy that actually does something.p=reject— mail that fails is refused at the door. The destination, once the reports show your own senders all authenticate.
The climb should be evidence-led: you tighten when the reports show your legitimate mail aligning, not on a calendar. That judgement — is this domain ready for the next step — is exactly what Sojka's readiness advisor automates.
The domain that sends nothing needs this more, not less
If you own domains that never send mail — parked names, defensive registrations, an old
brand — the ladder collapses: there is no mail of your own to protect, so there is nothing
to climb carefully past. Those domains can and should go to p=reject
immediately, with an SPF record that authorizes nobody. The exact records and the
reasoning are in the companion guide:
The domain that
sends no mail still needs DMARC.
Where to start
Check your domain free — it reads your published records and grades what is there. Then publish DMARC with a reporting address, and watch what comes back: Sojka reads the reports for you, names the senders, and says when the next policy step is safe.