DMARC tells receiving servers what to do with messages that fail SPF and DKIM aligned with your domain, and returns reports of who sends in your name. WebMon processes those reports and moves you from p=none to p=reject safely.
Home · Email security · DMARC
In short
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a public standard published as a TXT record at _dmarc.yourdomain. It defines a policy — none, quarantine or reject — and requests reports about mail sent in your domain's name.
When a server receives a message, it checks that it passes SPF or DKIM and that the From domain aligns with them. On failure it applies your DMARC policy and sends an aggregate report to the rua address you defined.
Any organization with its own domain that sends mail — marketing, transactional or payroll. It is especially critical for banking, healthcare and government, frequent spoofing targets.
It prevents exact spoofing of your domain: without DMARC at reject, an attacker can send mail that appears to come from you. With the policy enforced, those messages are rejected or quarantined.
Capabilities
Why it matters
FAQ
They are the three DMARC policies: none only monitors, quarantine sends suspicious mail to spam and reject blocks it outright. The recommendation is to start at none and advance using report data.
No. DMARC relies on SPF and DKIM: it checks that at least one passes and aligns with the From domain. Without SPF and DKIM correctly configured, DMARC has nothing to evaluate.
It can, if there are legitimate sources left unauthenticated. That is why WebMon first identifies and authenticates all your sources in none mode, and only then raises the policy gradually.
WebMon receives and processes your aggregate reports, translates the XML into clear sources, detects abuse and guides you to p=reject, backed by the SGS 24/7 SOC in Costa Rica.
Diagnose your domain with WebMon and see your DMARC record status today.
Diagnose your domain with WebMon