Set up DMARC from scratch
Set up DMARC by aligning SPF or DKIM on every legitimate sender, publishing one p=none record with monitored aggregate reporting, and moving to enforcement only after the reports show the real mailstreams are covered.
Gmail and Yahoo require bulk senders to publish DMARC and pass alignment; both accept p=none as the minimum policy. RFC 9989 recommends starting in monitoring mode because a forgotten platform or indirect mail flow can fail after enforcement. The right endpoint is not automatically p=reject: general-purpose domains and mailing-list participants need an explicit interoperability review.
Primary sources for this guidance
- RFC 9989 — Domain-Based Message Authentication, Reporting, and Conformance
- RFC 9990 — DMARC aggregate reporting
- Gmail email sender guidelines
- Yahoo Sender Hub best practices
How to fix it
- Inventory every system that uses the visible From domain, including marketing, transactional, support, CRM, security appliances and authorized third parties.
- Configure SPF and DKIM, then verify on received messages that at least one passing authenticated domain aligns with the visible From domain. Use aligned DKIM wherever forwarding is plausible.
- Create an aggregate-report destination that is access-controlled and actually parsed. If it is on another domain, complete the required external reporting authorization.
- Publish one TXT record at _dmarc.yourdomain, starting with an explicit record such as v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.
- Observe reports across the domain's real sending cadence. RFC 9989 notes that complex estates may need months; do not substitute an arbitrary short window for evidence that every legitimate stream is aligned.
- Remediate legitimate failures before enforcement. Record the From domain, Return-Path, DKIM domain, selector, ESP and owner for each stream.
- Choose p=quarantine when you are ready to enforce with review. Use p=reject only for a controlled domain after assessing forwarding, aliases and mailing-list use; general-purpose domains can have material interoperability risk.
- Do not use the historic pct tag as a new percentage rollout mechanism. Stage by domain or subdomain, keep aggregate reporting active and review the newer t testing semantics separately for receiver compatibility.
- Set sp and np deliberately for subdomains and non-existent names, then retest a fresh production-path message after DNS propagation and each policy change.
Limitations
A setup guide cannot discover every authorized sender or predict every indirect mail path. Aggregate reports are incomplete when receivers do not send them, and a DMARC pass does not guarantee inbox placement.