Folderly Flash Send-readiness test

Set up DMARC from scratch

Set up DMARC by aligning SPF or DKIM on every legitimate sender, publishing one p=none record with monitored aggregate reporting, and moving to enforcement only after the reports show the real mailstreams are covered.

Why mailbox providers enforce this

Gmail and Yahoo require bulk senders to publish DMARC and pass alignment; both accept p=none as the minimum policy. RFC 9989 recommends starting in monitoring mode because a forgotten platform or indirect mail flow can fail after enforcement. The right endpoint is not automatically p=reject: general-purpose domains and mailing-list participants need an explicit interoperability review.

Primary sources for this guidance

How to fix it

  1. Inventory every system that uses the visible From domain, including marketing, transactional, support, CRM, security appliances and authorized third parties.
  2. Configure SPF and DKIM, then verify on received messages that at least one passing authenticated domain aligns with the visible From domain. Use aligned DKIM wherever forwarding is plausible.
  3. Create an aggregate-report destination that is access-controlled and actually parsed. If it is on another domain, complete the required external reporting authorization.
  4. Publish one TXT record at _dmarc.yourdomain, starting with an explicit record such as v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.
  5. Observe reports across the domain's real sending cadence. RFC 9989 notes that complex estates may need months; do not substitute an arbitrary short window for evidence that every legitimate stream is aligned.
  6. Remediate legitimate failures before enforcement. Record the From domain, Return-Path, DKIM domain, selector, ESP and owner for each stream.
  7. Choose p=quarantine when you are ready to enforce with review. Use p=reject only for a controlled domain after assessing forwarding, aliases and mailing-list use; general-purpose domains can have material interoperability risk.
  8. Do not use the historic pct tag as a new percentage rollout mechanism. Stage by domain or subdomain, keep aggregate reporting active and review the newer t testing semantics separately for receiver compatibility.
  9. Set sp and np deliberately for subdomains and non-existent names, then retest a fresh production-path message after DNS propagation and each policy change.

Limitations

A setup guide cannot discover every authorized sender or predict every indirect mail path. Aggregate reports are incomplete when receivers do not send them, and a DMARC pass does not guarantee inbox placement.

Next action Publish the monitoring record only after aligned SPF or DKIM works, then send a representative production-path message to Flash. Do not advance policy until aggregate reports cover the estate's real sending cadence.
Run a free test →

FAQ

What is a safe first DMARC record?
Use one explicit monitoring record such as v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain, backed by a mailbox or service that parses the reports. Customize the reporting address and protect its access.
Do Gmail and Yahoo require DMARC enforcement?
Their published bulk-sender minimum accepts p=none, but the direct message still needs to pass DMARC alignment. Quarantine or reject is a separate anti-spoofing decision that must fit the domain's mail flows.
Can enforcement break legitimate mail?
Yes. A legitimate but unaligned platform, forwarding path or mailing-list flow can fail. Monitoring and aligned DKIM reduce the risk, but receiver local policy still controls final handling.

Related

Content record Owner: Folderly Flash content operations Reviewed: 2026-08-11 Maintenance trigger: Review when the IETF updates DMARC or aggregate reporting, Gmail or Yahoo changes bulk-sender requirements, or Flash changes its DMARC DNS parser.
Want a deliverability engineer to fix this for you? Hand it to Folderly →