p=none
Your DMARC policy is p=none. It watches spoofing happen - and blocks none of it.
p=none tells receivers: check my mail, send me reports, but deliver everything anyway - even messages that fail. It is the correct starting point, because it generates the data you need. But it was designed as a temporary phase, and most domains never leave it. A spoofer sending invoices as your domain faces no DMARC obstacle at all while your policy says none.
The record in question
$ dig +short TXT _dmarc.example.com "v=DMARC1; p=none; rua=mailto:dmarc@example.com"
Everything here works - reports flow, receivers evaluate alignment. The only thing missing is any consequence for mail that fails. That is what p=quarantine and p=reject add.
First: check where your domain stands
Run a free scan of your DMARC, SPF and DKIM records. It takes seconds and shows your current policy and what is keeping you from enforcement.
How to fix it, step by step
- 1
Make sure reports are actually collected
p=none without a rua address is pure decoration - nobody sees the results. Confirm your record has rua= pointing at a mailbox or reporting service someone actually reads. The reports are XML files sent by Gmail, Microsoft and others, roughly daily.
- 2
Read the reports for two to four weeks
The aggregate reports show every source sending as your domain and whether each passes SPF and DKIM with alignment. You are looking for two things: legitimate senders that fail (a forgotten invoicing tool, a CRM without DKIM) and unknown sources - which are either shadow IT or active spoofing.
- 3
Fix the legitimate senders that fail
For each real sender that fails: add it to SPF, enable DKIM signing with your domain, or move it to a subdomain with its own records. Do not tighten the policy until every source you recognize passes - otherwise you will quarantine your own mail.
- 4
Move to p=quarantine, then p=reject
Once reports show clean passes for all legitimate mail, switch to p=quarantine - failing mail goes to spam instead of the inbox. You can phase it in with pct (pct=25, then 50, then 100). After a clean stretch at full quarantine, finish at p=reject: spoofed mail is refused outright, which is the point of DMARC.
- 5
Keep watching after you tighten
Enforcement is not the end state - drift is. New tools get added without DKIM, vendors rotate keys, an SPF include breaks. The domains that stay protected are the ones where someone keeps reading the reports after reaching reject.
Related guides
Managing this for multiple client domains?
If you are an MSP or agency, a good share of your client base is probably parked at p=none with nobody reading the reports. DMARC Fleet is building continuous monitoring with per-client white-label reports - transparent pricing from $29/mo for 10 domains. Join the waitlist.