Build a valid DMARC TXT record with the right policy, reporting addresses, and alignment mode. Includes the 30-60-90 day rollout playbook.
DMARC is not a "publish once and forget" record. The correct rollout takes 90 days minimum to avoid blocking legitimate mail you forgot to authenticate.
p=none with rua= reporting. Collect aggregate reports. Identify every legitimate sender - ESP, transactional service, monitoring tool, calendar invites, vendor notifications. Fix any with broken SPF/DKIM alignment.p=quarantine; pct=25. Watch reports daily for legitimate mail being quarantined. Slowly ramp pct to 100 over 30 days.p=reject; pct=25, then 50, 75, 100. By day 90, spammers can no longer spoof your domain at compliant receivers.Receivers send raw XML reports to your rua= address. Reading them manually is painful - they're verbose, count tens of thousands of records per day for active senders. Use a free parser:
DMARC passes if EITHER SPF or DKIM passes WITH ALIGNMENT. Alignment means the From-domain matches the domain that authenticated.
Common breakage: you send via SendGrid with From: [email protected], but SendGrid uses MAIL FROM: [email protected]. SPF passes (sendgrid.net SPF is fine), but alignment fails (sendgrid.net ≠ yourdomain.com). DMARC fails unless DKIM aligns. Fix: configure custom DKIM at SendGrid using d=yourdomain.com.
Covers alignment in depth, multi-provider DKIM, the 30-day rollout, and how to fix common failures.
Read the guideSingle-email checks, no signup required
Validate DKIM records and selectors
Validate and debug your DMARC record
Validate and debug your SPF record
Build an SPF record for Google, M365, SendGrid
Check MX records and priority
Test your email before you send
Continue through related topics