What Is DMARC? Email Authentication and Alignment Explained
DMARC builds on SPF and DKIM. It checks whether authenticated domains align with the domain shown to the recipient and lets domain owners publish handling and reporting preferences.
Why DMARC exists
SPF and DKIM authenticate technical identities used during email delivery, but those identities can differ from the From address that users see. DMARC adds alignment so that at least one authenticated identity is meaningfully related to the visible From domain.
This makes DMARC particularly relevant to domain spoofing and sender-policy enforcement.
DMARC alignment
DMARC can pass through SPF alignment or DKIM alignment. Only one aligned authentication path is required for DMARC to pass.
Alignment can be relaxed or strict. Relaxed alignment permits certain organizational-domain relationships, while strict alignment requires a closer domain match.
DMARC policies
The p= tag expresses the requested policy for messages that fail DMARC. Common values are none, quarantine and reject.
Policy is only one part of the record. Reporting destinations, percentage settings, subdomain policy and alignment modes can also matter.
DMARC reports
Aggregate reporting can provide visibility into systems sending mail using a domain. External reporting destinations may require additional DNS authorization at the receiving report domain.
Reports are useful for identifying legitimate sources before enforcement is tightened.
Free email diagnostics
FreeMailCheck provides free tools for SPF, DKIM, DMARC, DNS, SMTP, TLS, reverse DNS, email headers and sender compliance.
Browse all 61 tools →