Our advice: do not ramp up DMARC by percentage (pct=). Ramp up once your reports show every service that sends as you is proving it is yours.
The pct= trap
Many older guides say to set pct=10, then 25, then 50. That applies your policy to a random share of failing mail, including any legitimate mail that is failing, without telling you which senders are affected. People can lose mail for weeks before anyone notices. A policy that covers only part of your mail also holds your security grade down, because it is not a full enforcement policy.
The report-driven path
- 1. Stay at
p=noneuntil your reports show every legitimate service proving it is yours. On the Email page, the domain's summary tells you when you are ready, and Check if you're ready on the domain's status takes you there. - 2. Move to
p=quarantineand watch your reports for one to two weeks. - 3. If nothing legitimate is going to spam, move to
p=reject. - 4. Make sure subdomains are covered too, with
sp=rejector by leavingsp=out so it inheritsp=reject. An unprotected subdomain is one of the most common gaps we find on otherwise well-configured domains.
Check the cost before you publish
What receivers do with fakes shows what would happen to your real mail if receivers sent fakes to spam or refused them, using your own report data. Open it from the policy label, such as Monitoring only, at the right of the domain's title row on the Email page. Compare all three shows monitoring only, spam and blocking side by side. Read it this way:
- Spoofed mail is left out of the headline figure, so an attacker cannot make you look more or less ready by sending more or less of it.
- Mail lost to forwarding is shown on its own line and never as something to fix, because no DNS record of yours can fix it.
- Senders we cannot identify are left out of the figure and stop it from saying you are ready until someone has looked at them.
- With fewer than 100 messages or 5 days of reports, it tells you how much data it has so far instead of making a prediction.
How long it takes
A simple setup with one or two senders can usually reach p=reject in about 2 to 4 weeks, while an organisation with many services sending as it typically takes 2 to 3 months. The pace is set by your reports confirming that every legitimate sender passes, not by a calendar.
We do not email you when you are ready. Instead, once a verified domain has reports from at least 14 days at its current policy and at least 95% of its email passes DMARC (98% before blocking), Home shows a to-do under Coming up, such as Looks ready to send fakes to spam. Treat it as a prompt to look, not a verdict: open the Email page and check that none of your own services is failing before you change anything. Until it appears, check the Email page every week or two while you are ramping up.