DNS & Setup

DMARC Records: A Field Guide for Cold Senders

What a DMARC record actually does, how to read one, and why p=none is not the same as being protected.

DMARC Records: A Field Guide for Cold Senders

DMARC (Domain-based Message Authentication, Reporting and Conformance) is the DNS record that tells receiving mail servers what to do when a message claims to be from your domain but fails SPF and DKIM checks. Without it, that decision is left entirely to each mailbox provider's own judgment.

Since February 2024, Gmail and Yahoo require a DMARC record for any domain sending meaningful volume to their users — it's no longer optional for cold outreach.

Anatomy of a DMARC record

A DMARC record lives in DNS as a TXT record at _dmarc.yourdomain.com. A minimal example:

v=DMARC1; p=none; rua=mailto:[email protected]

TagMeaningCommon values
vProtocol versionDMARC1 (always)
pPolicy for the domain itselfnone, quarantine, reject
spPolicy for subdomainsnone, quarantine, reject
ruaWhere to send aggregate reportsmailto: address
rufWhere to send forensic (failure) reportsmailto: address
pct% of failing mail the policy applies to1-100
adkim / aspfStrict or relaxed alignments (strict), r (relaxed)

p=none, quarantine, reject — what each actually does

  • p=none: Monitor only. Failing mail is delivered normally, but you receive reports showing what's failing and from where. This is the required starting point — never skip straight to enforcement.
  • p=quarantine: Failing mail is routed to spam/junk instead of the inbox.
  • p=reject: Failing mail is rejected outright at the mail server, never delivered.

Meeting Gmail and Yahoo's 2024 bulk-sender requirement only requires a record that exists — even p=none satisfies it. But p=none provides no actual protection against spoofing; it's purely observational.

A rollout plan that doesn't break your own mail

Jumping straight to p=reject on a domain with unaudited sending sources (marketing tools, CRM, transactional email, cold outreach platforms) is the single most common cause of self-inflicted deliverability outages. The correct sequence:

  1. Weeks 1-2: Publish p=none with rua reporting enabled. Do nothing else.
  2. Weeks 2-4: Read the aggregate reports (a parser like dmarcian or Postmark's free tool makes raw XML readable). Identify every legitimate source sending as your domain.
  3. Confirm SPF and DKIM pass for every legitimate source — fix any that don't before moving forward.
  4. Move to p=quarantine at pct=25, watch reports for a week, then increase pct gradually.
  5. Move to p=reject only once quarantine has run clean for several weeks.

Why this matters more for cold senders specifically

Cold email domains are exactly the kind of domain spoofers target, because a plausible-looking sales domain raises less suspicion than a well-known brand. A domain with no DMARC record — or one stuck at p=none indefinitely — is both easier to spoof and, per the 2024 bulk sender rules, at higher risk of being throttled or rejected outright by Gmail regardless of how well warmup and content are handled elsewhere.

Bottom line

DMARC is not a switch you flip once — it's a staged rollout from visibility to enforcement. Get p=none live today if you don't have it, read the reports for a few weeks, and only tighten the policy once you know exactly what's sending on your domain's behalf.

Ready for liftoff?

Your next campaign is six minutes away

Connect your business and let Alien AI handle the writing, structuring, and optimizing.

Generate my Business DNA — free