Audit an existing DMARC record
Audit DMARC by checking the record, the aligned identity on a real message, report flow and the policy's fit for this domain. A syntactically valid TXT record is only the first of those four checks.
Gmail and Yahoo require bulk senders to publish DMARC and pass alignment, but both accept p=none as the minimum policy. RFC 9989 defines monitoring and enforcement more precisely, removes the historic pct tag, and warns that p=reject can disrupt legitimate indirect mail for general-purpose domains. DMARC validates use of the From domain; it does not guarantee inbox placement or force every receiver to apply the requested disposition.
Primary sources for this guidance
- RFC 9989 — Domain-Based Message Authentication, Reporting, and Conformance
- RFC 9990 — DMARC aggregate reporting
- Gmail email sender guidelines
- Yahoo Sender Hub best practices
How to fix it
- Inspect a representative received message. Confirm that SPF or DKIM passes and that at least one authenticated domain aligns with the visible From domain under the published aspf or adkim mode.
- Query _dmarc.yourdomain and keep one valid DMARC1 TXT record. Check p, sp, np, rua, ruf, adkim, aspf and t only when each tag expresses an intentional policy.
- Treat pct as historic under RFC 9989. Some older receivers and tools may still interpret it, so remove it through a reviewed compatibility change rather than relying on it for percentage rollout.
- Verify that aggregate reports arrive and are parsed. If a rua destination is on another domain, confirm the external reporting authorization required by the current reporting specification.
- Inventory every legitimate sender in the reports and remediate any stream that does not pass aligned SPF or DKIM. Prefer a durable aligned DKIM signature for mail that may be forwarded.
- Choose policy for the domain's actual use: p=none for observation, p=quarantine for enforcement with review, and p=reject only when authorized streams and indirect-flow risks are understood.
- Review subdomain and non-existent-domain handling with sp and np. Active mailstreams may need explicit records; unused names can usually take a stricter policy.
- Retest a fresh production-path message after DNS propagation, then keep monitoring reports and receiver outcomes. A DMARC pass proves aligned identity for that message, not future placement.
Limitations
This audit checks published policy and the identities visible on the tested message. It cannot inventory an entire sending estate from one email, prove that every receiver honors the requested policy, or guarantee inbox placement.