Build a valid DMARC TXT record with the right policy, reporting addresses, and alignment mode. Includes the 30-60-90 day rollout playbook.
DMARC is not a "publish once and forget" record. The correct rollout takes 90 days minimum to avoid blocking legitimate mail you forgot to authenticate.
p=none with rua= reporting. Collect aggregate reports. Identify every legitimate sender - ESP, transactional service, monitoring tool, calendar invites, vendor notifications. Fix any with broken SPF/DKIM alignment.p=quarantine; pct=25. Watch reports daily for legitimate mail being quarantined. Slowly ramp pct to 100 over 30 days.p=reject; pct=25, then 50, 75, 100. By day 90, spammers can no longer spoof your domain at compliant receivers.Receivers send raw XML reports to your rua= address. Reading them manually is painful - they're verbose, count tens of thousands of records per day for active senders. Use a free parser:
DMARC passes if EITHER SPF or DKIM passes WITH ALIGNMENT. Alignment means the From-domain matches the domain that authenticated.
Common breakage: you send via SendGrid with From: [email protected], but SendGrid uses MAIL FROM: [email protected]. SPF passes (sendgrid.net SPF is fine), but alignment fails (sendgrid.net ≠ yourdomain.com). DMARC fails unless DKIM aligns. Fix: configure custom DKIM at SendGrid using d=yourdomain.com.
Covers alignment in depth, multi-provider DKIM, the 30-day rollout, and how to fix common failures.
Read the guide