Learn · Updated July 2026

DMARC

DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email standard that tells receiving mail servers what to do with messages that fail SPF or DKIM checks — and sends you reports. It prevents spoofing of your domain and is now effectively required by Gmail and Yahoo for bulk senders.

How it works

You publish a DMARC policy as a DNS TXT record. It sets a policy (none / quarantine / reject) for unauthenticated mail claiming to be from your domain, and an address to receive aggregate reports.

Why it matters

Without DMARC, anyone can spoof your domain, and major providers may throttle or reject your legitimate bulk mail. A 'reject' or 'quarantine' policy protects your brand and your deliverability.

How Autocloz handles it

Autocloz monitors SPF, DKIM and DMARC for every connected sending domain and flags misconfigurations before they tank a campaign.

FAQ

Is DMARC required?

Since 2024, Gmail and Yahoo require SPF, DKIM and a DMARC policy for bulk senders. Even below bulk thresholds, DMARC materially improves deliverability and blocks spoofing.

What DMARC policy should I use?

Start at p=none to collect reports, confirm your legitimate mail passes SPF/DKIM aligned, then move to quarantine and finally reject.

Related terms

Sources