How SPF, DKIM and DMARC work together
SPF lists the servers allowed to send email for a domain. DKIM adds a cryptographic signature that proves a message was not altered and comes from an authorised sender. DMARC builds on both: it checks that the domain the recipient sees matches the one verified by SPF or DKIM, applies the policy published in the domain's DNS, and sends reports on who is sending email in its name.
The three policies
p=none only monitors and reports. p=quarantine sends failing messages to spam. p=reject blocks them. The usual approach is to start with none, use the reports to find every legitimate sender (marketing tools, CRM, invoicing software), fix their configuration and then move to quarantine and reject. A DMARC record left at none protects nothing.
Why it matters
Without DMARC, anyone can send an email that appears to come from your exact domain, a common starting point for phishing and BEC fraud against customers, suppliers and employees. Since 2024, Google and Yahoo require DMARC from bulk senders. DMARC does not stop lookalike domains, so awareness training is still needed. The DMARC.org site explains the standard and links to its specification.




