DMARC builds on SPF and DKIM. It tells receiving mail servers what to do when a message claims to come from your domain but cannot prove it.
The core idea
Every email has a From address that people see, such as invoices@yourcompany.com. SPF checks a different, hidden address (the envelope sender), and DKIM checks the domain that signed the message. Neither has to match the From address, so an attacker can pass both with a domain of their own while still showing yours.
DMARC adds the missing check, called alignment: a message passes only when SPF or DKIM passes for your domain. See what SPF, DKIM and DMARC each check.
Three policies
-
p=none: monitoring only. Receivers deliver failing mail as normal and send you reports. -
p=quarantine: failing mail goes to spam. -
p=reject: failing mail is refused.
In ShieldMarc these show as Monitoring only, Fakes to spam and Blocking on.
What ShieldMarc does
Receivers send DMARC aggregate reports to your ShieldMarc reporting address. We turn them into the Email page: who sends email as your domain, and whether each message proved it was yours. Senders are grouped into Needs a fix, for your own services that need a settings or DNS change; Senders we do not recognise; and Working as expected, which includes forwarded mail and is collapsed while anything else needs your attention.
Before you tighten your policy, What receivers do with fakes uses your own report data to show what would happen to your real mail if receivers sent fakes to spam or refused them. Open it from the policy label, such as Monitoring only, at the right of the domain's title row on the Email page, or follow DMARC policy progression.