Setup & Records

Enforcement Guide: are you ready for quarantine or reject?

Most domains sit at p=none for years because nobody is sure what will break if they tighten it. The Enforcement Guide answers that question using your own report data.

Where to find it
Setup & Records → Enforcement Guide

What you'll see

At the top, a three-step tracker (none → quarantine → reject) shows where your policy is today. Under it, a readiness verdict:

  • Ready for Enforcement. More than 95% of your mail already passes DMARC. Tightening the policy will only affect the failing 5%, and the table below tells you who they are.
  • Not Ready Yet. Shown with your actual pass percentage. Some legitimate senders are still failing; fix them first.

The Unverified Sources table lists every sender currently failing, grouped by hostname with a logo, IP addresses, how much mail it sends, and whether it fails SPF, DKIM or both. This is your to-do list before you tighten anything.

How to use it

  1. Work through the failing senders

    For each row, decide: is this a service we use? If yes, get it authenticated (add it to SPF, turn on DKIM at the vendor). If no, it's spoofing, and enforcement is exactly what will stop it.

  2. Wait for the verdict to turn green

    Fixes show up in reports within a day or two.

  3. Change the policy

    This page only tells you whether you're ready. To actually change the policy, use Smart DMARC (or its Auto-advance ladder), or update the p= value in your DMARC TXT record.

The guide is built from whichever DMARC report is currently loaded, so make sure the date range in the header covers at least a couple of weeks of normal sending, including any monthly newsletters or invoicing runs.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support