← Back to blog
Glossary · DMARC

What is DMARC?

DMARC resolves the one thing SPF and DKIM cannot decide on their own: what happens after an authentication check fails.
1 min read · Updated August 2026

DMARC is a DNS record that tells receiving mail servers what to do with a message that fails SPF or DKIM alignment, and where to send a report about it. It resolves the one thing SPF and DKIM cannot decide on their own: what happens after a check fails.

A DMARC record passes when SPF or DKIM produces a pass whose authenticated identifier aligns with the domain in the visible From address, not merely when SPF or DKIM pass on their own. The policy tag, p, takes none, quarantine, or reject. RFC 9989, in force since May 2026, replaced the earlier RFC 7489 specification and removed the older pct tag that used to roll a policy out to a percentage of mail at a time.

The distinction I see missed most: a domain can have SPF and DKIM both passing independently and still fail DMARC, because alignment, not just a pass, is the actual condition. This is exactly why moving to p=reject exposes mail that looked fine under SPF and DKIM checked separately.

Not sure your DMARC record is actually aligned?
Run the free diagnostic and I will confirm SPF, DKIM and DMARC alignment together, not one at a time.
Start the free diagnostic →
Julian Turgelski
The Diagnostic Blog
hello@julianturgelski.com
Julian's diagnostic console