Support

Oh noes! We're sorry that things like suck, and stuff, that sucks. Drop us some deets and we'll get Son of Anton right on it.

Application home Website home

Frequently asked questions

Clear answers for teams evaluating DMARC for the first time or planning a move from monitoring to enforcement.

DMARC is a DNS-based policy that tells receiving mail servers how to handle email that claims to be from your domain but fails authentication, and it tells them where to send reports so you can see what is happening.

Yes. Bulk-sender rules are one driver, but DMARC also protects your domain from spoofing, gives visibility into who is sending as you, and may still be relevant for PCI DSS or sector expectations.

p=none is monitoring only. p=quarantine tells receivers to treat failures with suspicion, usually routing them to spam. p=reject tells receivers to block authentication failures outright.

Not if it is implemented correctly. Starting with p=none has no delivery impact. Problems usually happen when organisations enforce too early without first authenticating all legitimate sending sources.

They are daily XML reports from receiving mail servers showing sending IPs, SPF and DKIM outcomes, alignment, and what policy was applied to mail claiming to be from your domain.

No. DMARC is highly effective against direct domain spoofing, but it does not stop look-alike domains, display-name impersonation, or compromised accounts.