Setup & how-to

Setting up DMARC

You set up DMARC with a single TXT record in your domain's DNS management. That record builds on SPF and DKIM: it tells receiving servers what to do with mail that pretends to be from your domain but doesn't pass the checks. Think of it as the final layer on top of your guest list and your wax seal: SPF and DKIM check the sender, DMARC decides the consequences. You start deliberately cautious with monitoring only, then tighten it later. Don't worry, you don't need any technical knowledge for this.

By the Mailflux team Published on

Reading and managing email in webmail, on any device

What you need

  • A Mailflux mailbox on your own domain.
  • Access to the DNS management at your domain registrar or hosting provider.
  • A working SPF and DKIM record. DMARC leans on those two, so get them right first. You can read at your leisure how it all fits together in email DNS records explained.
  • An email address where you want to receive the reports.

Setting up DMARC: step by step

  1. First check whether SPF and DKIM are already active. Without those two, DMARC has no foundation to build on.
  2. Log in to your domain registrar and open the DNS management for your domain.
  3. Click Add record and choose TXT as the type.
  4. Under Name (or Host) enter exactly _dmarc. Some registrars automatically append your domain, which is normal.
  5. Under Value enter your DMARC text. The structure is standard and looks like this:

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

  1. Replace yourdomain.com with your own domain, so the reports come to you.
  2. Save the record. Done.

What does that policy (p=) mean?

The p= part determines what happens to mail that fails the check. Always start with p=none: nothing about delivery changes yet, but you do receive reports (rua) that show who is sending on behalf of your domain. That way you spot silent problems without a real mail being dropped.

If everything checks out after a few weeks, you tighten it. Set p=quarantine to have suspicious mail land in the spam folder, and later p=reject to refuse it entirely. That progression from none to quarantine to reject is the safe route: you build trust before you close the door. If you first want to understand what's happening under the hood, read what is DMARC.

Not working?

  • You're not receiving reports. Check that the address after rua=mailto: is correct and that the TXT record is on the name _dmarc.
  • There are two DMARC records. Just like with SPF, you may only have one. Combine everything into that single TXT record starting with v=DMARC1.
  • Legitimate mail disappears after p=reject. Then SPF or DKIM wasn't fully correct yet. Temporarily set p= back to none, fix the underlying records and then tighten again.
  • The change doesn't seem active. DNS changes can take up to 24 hours. Give it some time and check again.

Almost done

Once your DMARC record is active on p=none, you monitor via the reports for a while and then calmly tighten it to quarantine or reject. If you're also going to use your mailbox in a program, the details are ready at the IMAP server settings. Can't work it out with your DNS? Let us know, we're happy to take a look or set it up for you.

Ready to get started yourself?

Follow our step-by-step guide, or let us help you get set up personally.

Read the guide

FAQ

Frequently asked questions

Do I need SPF and DKIM before I set up DMARC?

Yes. DMARC checks whether mail was approved by SPF or DKIM and acts accordingly. Without those two records, DMARC has nothing to lean on and legitimate mail can be wrongly rejected. So get SPF and DKIM right first, and add DMARC afterwards as the final layer.

Which policy should I start with?

Start with p=none. With that, nothing changes about delivery, but you do receive reports about who is sending on behalf of your domain. If everything checks out after a few weeks, you move on to quarantine and eventually to reject. That way you build up protection step by step without losing real mail.