Start by watching
Nothing changes for your mail; you receive daily reports of every server sending as your domain. It meets Gmail and Yahoo's rule for bulk senders.
Pick a policy and where reports go. You get the record, the exact place to publish it, and what to watch out for.
p=none — reports only. Start here.
Relaxed lets mail sent from a subdomain (news.example.fr) count for example.fr. Keep it unless you know you need strict.
v=DMARC1; p=noneNo report address: you won't see who sends mail as your domain, which is the reason to start with p=none.
p=none only asks for reports. It meets Gmail and Yahoo's rule; move to quarantine once the reports show all your real mail passing.
Most DNS hosts want just _dmarc as the name. Once it's live, check it.
DMARC ties SPF and DKIM to the address people see in From, tells receivers what to do when both fail, and sends you reports.
Nothing changes for your mail; you receive daily reports of every server sending as your domain. It meets Gmail and Yahoo's rule for bulk senders.
Once the reports show your real mail passing, failing mail goes to the spam folder. Raise it gradually with pct if you're unsure.
Spoofed mail is refused outright. The end state for a domain that sends — it protects your name and your reputation.
Aggregate reports are XML files, one per receiver per day. A free report service turns them into a list of senders to approve.
Read more: SPF, DKIM and DMARC explained · SPF generator
Mailbase writes SPF, DKIM, DMARC and the reply MX when you add or buy a domain, then raises its volume only while real bounces and complaints stay low.