Smart DMARC: change your DMARC policy without editing DNS
Every time you tighten your DMARC policy you normally have to edit a DNS TXT record by hand. Smart DMARC replaces that with a form in DMARCS: one CNAME record at your DNS provider, and after that every change is a click.
- Where to find it
- Setup & Records → Smart DMARC
- Time needed
- 5 minutes, plus DNS propagation
- You will need
- One CNAME record added at your DNS provider
How it works
Instead of your DNS holding the DMARC record itself, it holds a CNAME (an alias) that points _dmarc.yourdomain.com at a record DMARCS hosts for you. When you change the policy in DMARCS, the record everyone sees changes within moments. No DNS ticket, no waiting on someone else.
Set it up
- Pick the domain
Open Smart DMARC and choose the domain from the dropdown.
- Add the CNAME at your DNS provider
DMARCS shows you the exact CNAME to publish. It replaces any existing
_dmarcTXT record, so delete the old TXT first (a host can't have both a CNAME and a TXT).Before you save, DMARCS compares what you are about to publish with what is already live and warns you about conflicts, for example a second DMARC record or a policy that would loosen protection you already have. - Set the policy
Choose none, quarantine or reject, and a percentage. When first tightening, start low (10% is a sensible first step) so a mistake only affects a slice of your mail. You can also set your own report addresses and alignment mode here, but the defaults are right for almost everyone.
- Save
Click save. The new record is live globally within moments.
Let DMARCS tighten the policy for you
Once the CNAME is in place you can switch on Auto-advance. DMARCS then moves your policy up a fixed ladder, one rung at a time, only when your real report data says it's safe:
none → quarantine 25% → quarantine 50% → quarantine 100% → reject 50% → reject 100%
Pick a target (quarantine or reject) and DMARCS handles the steps. Each step only happens when your pass rate and volume are high enough that legitimate mail won't be caught. If you'd rather stay in control, leave Auto-advance off and click Advance now yourself when the readiness check says you're ready.
What the three policies mean
| Policy | What receivers do with mail that fails DMARC |
|---|---|
none | Deliver it as normal, but send you a report. Monitoring only. |
quarantine | Put it in spam or junk. |
reject | Refuse it outright. This is the goal: spoofed mail never reaches an inbox. |
Not sure whether you're ready to move up? The Enforcement Guide gives you a plain yes or no, and lists every sender that would be affected.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.