Why DMARC is worth having before anything goes wrong

Email was designed so that the From line is just text. Anyone, anywhere, can send a message that says it is from your domain, and nothing in the protocol stops them. SPF and DKIM exist to prove where mail really came from — but on their own they carry no instruction, and a receiver that sees them fail is left to guess. DMARC is the missing piece: a DNS record that ties those checks to the visible From address and tells every major receiver, in advance, what to do when a message claiming your name fails them.

What you get on day one

The first thing DMARC gives you is not protection — it is sight. A record with p=none changes nothing about delivery; it simply asks receivers to send you daily aggregate reports: which servers sent mail as your domain, how much, and whether it authenticated. Gmail, Microsoft, Yahoo and most large receivers honour it. Until you publish that request, those reports do not exist — there is no log to go back and read on the day you first need one.

Most domain owners are surprised by their own reports. A billing tool somebody signed up for years ago, a newsletter platform, a web server that sends password resets — and, often enough, senders that are nobody's: addresses on other continents putting your name on messages you never sent.

What it costs you to not have it

The ladder, and why it is a ladder

DMARC has three policies, and they are meant to be climbed in order — for a domain that sends mail, each step is a promise that your own messages will survive it.

The climb should be evidence-led: you tighten when the reports show your legitimate mail aligning, not on a calendar. That judgement — is this domain ready for the next step — is exactly what Sojka's readiness advisor automates.

The domain that sends nothing needs this more, not less

If you own domains that never send mail — parked names, defensive registrations, an old brand — the ladder collapses: there is no mail of your own to protect, so there is nothing to climb carefully past. Those domains can and should go to p=reject immediately, with an SPF record that authorizes nobody. The exact records and the reasoning are in the companion guide: The domain that sends no mail still needs DMARC.

Where to start

Check your domain free — it reads your published records and grades what is there. Then publish DMARC with a reporting address, and watch what comes back: Sojka reads the reports for you, names the senders, and says when the next policy step is safe.