Blog
·5 min read

From p=none to p=reject in four steps

Enforcing DMARC at p=reject is the end goal: attackers can no longer send email pretending to be your domain. But jumping straight there is risky — you could block your own legitimate mail. Here’s the safe route.

1. Start at p=none and collect data

Publish a DMARC record with p=none and a rua address. Nothing is blocked; you collect reports showing who sends in your name. Plan for at least 7 days of data.

2. Classify every source

Don’t rely on a total percentage. Look at each sending source separately and decide whether it’s legitimate. Legitimate sources that fail must be fixed — usually missing DKIM.

3. Advance to p=quarantine

Once all your approved sources align reliably, tighten to quarantine. Suspicious mail now lands in spam. Keep monitoring for a week.

4. Advance to p=reject

No new legitimate source in the last week? Then reject is safe. DMARC-IT tracks this whole journey per source and tells you exactly when each step is safe.

DMARC-IT doet dit voor je.

Per-bron analyse en een assistent die je veilig naar p=reject begeleidt.

Gratis starten
From p=none to p=reject in four steps — DMARC-IT