Skip to main content

Email

How to Move from DMARC p=none to p=quarantine

DMARC at p=none is monitoring-only — spoofed emails still get delivered. The goal is p=reject. Here's how to get there without breaking legitimate mail.

Try our Email checker

1. Spend 2-4 weeks on p=none

Collect DMARC aggregate reports (rua=) and identify every legitimate sender — your ESP transactional service marketing platform helpdesk etc. Authorize each via SPF includes or DKIM signing.

2. Move to p=quarantine with pct=10

Apply quarantine to only 10% of failing mail. Watch reports for a week. If you see legitimate mail in quarantine fix authentication for that sender.

3. Ramp pct to 100

Bump pct=25 then 50 then 100 over a few weeks. Each step re-check reports and fix any newly-broken senders.

4. Switch to p=reject

Once you're at quarantine pct=100 and reports show no legitimate mail failing change p=quarantine to p=reject. Spoofers will be blocked outright.

Want to verify your setup?

Run the check now