Skip to main content

Email

What is DMARC, and why every business with a domain needs one.

Published 2026-05-01 · Last updated 2026-05-01 · Vantyris editorial

If your domain has no DMARC record, anyone can send an email from accounts@yourbusiness.co.uk to one of your customers, and it will land in their inbox looking real. Most phishing campaigns ride this path by default. DMARC is the single highest-impact thing a small business can fix on its email setup, and it costs nothing.

What this means for your business

How to fix

Add a DMARC TXT record at _dmarc.<yourdomain> starting with p=none to collect reports for a month, then move up to p=quarantine and finally p=reject.

  1. Make sure SPF is in place first. DMARC depends on SPF (or DKIM), so add SPF first if you don't have it. Look up your domain's TXT records. An SPF record starts with v=spf1. If there isn't one, add the basic record your email provider gives you.
  2. Decide where to receive aggregate reports. Pick an address for the daily DMARC reports. A dedicated mailbox like dmarc@yourbusiness.com works. A free aggregator (Postmark's free tier, Dmarcian, Easydmarc) goes a step further and parses the reports into a dashboard.
  3. Add the DMARC TXT record. At your DNS provider, create a new TXT record. Host: _dmarc (your DNS panel will append your domain automatically). Value: v=DMARC1; p=none; rua=mailto:dmarc@yourbusiness.com. Save.
  4. Wait a week, then check the reports. Reports trickle in from each major receiving server (Google, Microsoft, Yahoo). Confirm that every sender in them is legitimate. If a suspicious sender shows up, that's an impersonation attempt you've just made visible.
  5. Progress to quarantine, then reject. After about 4 weeks of clean reports, change p=none to p=quarantine. A month after that, change it to p=reject. From then on, unauthenticated mail from your domain bounces.

Owner: Your DNS administrator. Same person who sets your MX records. · Time: 30 minutes for the initial setup, 8 weeks in total to reach p=reject.

Common gotchas

How to verify the fix

Run a Vantyris teaser scan on your domain to see the DMARC record and its current policy. For a quick second check, paste your domain into mxtoolbox.com/dmarc.aspx. Within a week, aggregate reports should start arriving at your rua address. If they don't, the record isn't being read.

Cyber Essentials alignment

This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):

Vantyris is not a CE certifying body. The mapping above is informational.

Common follow-up questions

Is DMARC mandatory?

Not legally. But Gmail and Yahoo now require it from any sender pushing 5,000+ messages a day. Below that volume your delivery rates still suffer, and your customers are still exposed to impersonation. Nobody serious about email skips DMARC any more.

What's the difference between DMARC and BIMI?

BIMI shows your logo next to your name in Gmail. It only works if you already have DMARC at p=quarantine or stricter. DMARC is the prerequisite. BIMI is the brand polish on top.

Can DMARC break my newsletter?

If your newsletter ESP isn't authenticated, yes. The fix is to authenticate the ESP, not to drop DMARC. Most reputable ESPs walk you through SPF and DKIM setup when you sign up.

References

Related explainers

Want Vantyris to check your domain for this and 196 other problems?

The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.

Written by Vantyris