DMARC p=none does not stop phishing. Here's what to do instead.
Published 2026-04-01 · Last updated 2026-04-01 · Vantyris editorial
If your domain's DMARC record sets p=none, your policy is in monitor-only mode. Receiving mail servers accept impersonated email from your domain and only send you a report about it afterwards. That's useful for the first month, while you read the reports. Every week after that is a week you've left the front door open.
What this means for your business
- Anyone can send email from your domain to a Gmail or Outlook user, and it will land in their inbox looking legitimate. Your customers can be phished through your domain right now.
p=nonewas designed as a staging mode. You publish it for 4 to 8 weeks and read the aggregate reports until you're sure none of your own legitimate mail is failing SPF or DKIM (newsletters, transactional mail, third-party senders). After that you graduate top=quarantine, and eventually top=reject.- If you've been on
p=nonefor more than 90 days, you almost certainly should have moved on. Most owners get stuck there because nobody read the aggregate reports and they were nervous about breaking legitimate mail.
How to fix
Once your aggregate reports are clean (no legitimate mail failing), change the TXT record from p=none to p=quarantine. Stay there for another month. If nothing broke, move to p=reject.
- Read your DMARC aggregate reports. Set up a free DMARC aggregator (Postmark, Dmarcian's free tier, or Easydmarc) and send your
rua=reports there for 2-4 weeks. Confirm every sender that appears in the report is legitimate (your transactional ESP, your newsletter tool, your accountant's CRM if it sends in your name). Make sure each one is SPF-authorised and DKIM-signed. - Change the DMARC TXT record. At your DNS provider, edit the existing TXT record at
_dmarc.<yourdomain>. Changep=nonetop=quarantine, and keeprua=so the reports keep flowing. Example:v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100. - Wait 30 days and confirm no legitimate mail broke. Watch the aggregate reports. If a third-party sender shows up failing alignment, fix that sender's SPF or DKIM. Don't move to
p=rejectuntil everything in the report is either authenticated or known junk. - Move to
p=reject. Final step. Edit the record again and changep=quarantinetop=reject. Unauthenticated mail claiming to come from your domain now bounces outright. The impersonation hole is closed.
Owner: Your DNS administrator. Most domain registrars have a DNS panel, and your web host's support team will know where it is. · Time: 10 minutes per DNS edit, with 4-8 weeks of monitoring between edits.
Common gotchas
- Don't skip the monitoring period. Going straight from
p=nonetop=rejectcan break legitimate mail, and you'll get blame-emails from people whose receipts vanished. - Make sure
rua=mailto:points at a real address you check. Without aggregate reports, you're flying blind. - Don't set the SPF record to
~alland call it good. SPF alone doesn't protect against impersonation. DMARC is the part that enforces.
How to verify the fix
Run a free Vantyris teaser scan to confirm the new record is published and parses cleanly. Any DMARC checker works too. Paste your domain into mxtoolbox.com/dmarc.aspx and check the policy reads quarantine or reject. After a week, your aggregate reports should show more than 99% of mail authenticated.
Cyber Essentials alignment
This finding informs the following Cyber Essentials control areas (the UK government's baseline scheme, a sound checklist in any country):
- A1. Firewalls: boundary protection between the internet and your services.
- A2. Secure configuration: devices and services hardened against the weaknesses they ship with by default.
Vantyris is not a CE certifying body. The mapping above is informational.
Common follow-up questions
Will moving off p=none break my email?
It can, if one of your senders isn't authenticated. That's why you sit on quarantine for a month first. Legitimate mail that fails lands in spam folders instead of disappearing, so it's recoverable.
What's the difference between SPF and DMARC?
SPF lists which servers are allowed to send for your domain. DMARC tells receiving servers what to do when SPF or DKIM fails. SPF without DMARC enforcement is observation without consequence.
Do I need DKIM as well?
Yes. DMARC requires either SPF or DKIM to pass and align. Most providers (Google Workspace, Microsoft 365, transactional ESPs) set DKIM up automatically. You only need to check it's running on each sender.
What's pct=100?
It applies the policy to 100% of mail. You can dial it down during the move (pct=10 quarantines just 10% while you watch), but most small senders go straight to 100.
References
- NCSC: email security and anti-spoofing NCSC
- RFC 7489: DMARC IETF RFC
- RFC 7489 §6.3: DMARC policy actions IETF RFC
Related explainers
- SPF records, explained: the first line of defence against email spoofing.
- What is DMARC, and why every business with a domain needs one.
Want Vantyris to check your domain for this and 196 other problems?
The teaser scan is free and needs no card. A verified scan starts at $10€10£10A$15¥1,500AED 40 and comes with the workspace: finding workflow, score trend, three PDF layouts, share links and monitoring.
Written by Vantyris