What is DMARC, and why every business with a domain needs one.
Published 2026-05-01 · Last updated 2026-05-01 · Vantyris editorial
If your domain has no DMARC record, anyone can send an email from accounts@yourbusiness.co.uk to one of your customers, and it will land in their inbox looking real. Most phishing campaigns ride this path by default. DMARC is the single highest-impact thing a small business can fix on its email setup, and it costs nothing.
What this means for your business
- Without DMARC, the big mailbox providers (Gmail, Outlook, Yahoo) have no reliable way to tell whether an email from your domain came from you or from an attacker. So they accept it, and your customer opens a convincing invoice or password reset that you never sent.
- DMARC is one TXT record at your DNS provider. Adding it costs nothing and takes about 30 minutes once you've found the right page in your registrar's control panel.
- DMARC works alongside SPF (which lists the servers allowed to send for you) and DKIM (which cryptographically signs your outgoing mail). It's the policy layer that tells receiving servers what to do when SPF or DKIM fails.
How to fix
Add a DMARC TXT record at _dmarc.<yourdomain> starting with p=none to collect reports for a month, then move up to p=quarantine and finally p=reject.
- Make sure SPF is in place first. DMARC depends on SPF (or DKIM), so add SPF first if you don't have it. Look up your domain's TXT records. An SPF record starts with
v=spf1. If there isn't one, add the basic record your email provider gives you. - Decide where to receive aggregate reports. Pick an address for the daily DMARC reports. A dedicated mailbox like
dmarc@yourbusiness.comworks. A free aggregator (Postmark's free tier, Dmarcian, Easydmarc) goes a step further and parses the reports into a dashboard. - Add the DMARC TXT record. At your DNS provider, create a new TXT record. Host:
_dmarc(your DNS panel will append your domain automatically). Value:v=DMARC1; p=none; rua=mailto:dmarc@yourbusiness.com. Save. - Wait a week, then check the reports. Reports trickle in from each major receiving server (Google, Microsoft, Yahoo). Confirm that every sender in them is legitimate. If a suspicious sender shows up, that's an impersonation attempt you've just made visible.
- Progress to quarantine, then reject. After about 4 weeks of clean reports, change
p=nonetop=quarantine. A month after that, change it top=reject. From then on, unauthenticated mail from your domain bounces.
Owner: Your DNS administrator. Same person who sets your MX records. · Time: 30 minutes for the initial setup, 8 weeks in total to reach p=reject.
Common gotchas
- DMARC at
p=nonestops nothing. It only reports. It's a staging mode, and you're meant to leave it. - You can only have ONE DMARC record per domain. If you already have one, edit it. Don't add a second.
- If you use third-party senders (newsletters, CRM, an accountant sending in your name), make sure each one is included in SPF and signs with DKIM. Otherwise their mail will fail DMARC once you tighten the policy.
How to verify the fix
Run a Vantyris teaser scan on your domain to see the DMARC record and its current policy. For a quick second check, paste your domain into mxtoolbox.com/dmarc.aspx. Within a week, aggregate reports should start arriving at your rua address. If they don't, the record isn't being read.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A1. Firewalls: boundary protection between the internet and your services.
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Is DMARC mandatory?
Not legally. But Gmail and Yahoo now require it from any sender pushing 5,000+ messages a day. Below that volume your delivery rates still suffer, and your customers are still exposed to impersonation. Nobody serious about email skips DMARC any more.
What's the difference between DMARC and BIMI?
BIMI shows your logo next to your name in Gmail. It only works if you already have DMARC at p=quarantine or stricter. DMARC is the prerequisite. BIMI is the brand polish on top.
Can DMARC break my newsletter?
If your newsletter ESP isn't authenticated, yes. The fix is to authenticate the ESP, not to drop DMARC. Most reputable ESPs walk you through SPF and DKIM setup when you sign up.
References
- NCSC: email security and anti-spoofing NCSC
- RFC 7489: DMARC IETF RFC
- Google + Yahoo bulk sender requirements (2024) Vendor
Related explainers
- DMARC p=none does not stop phishing. Here's what to do instead.
- SPF records, explained: the first line of defence against email spoofing.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris