How to Move from DMARC p=none to p=quarantine
DMARC at p=none is monitoring-only — spoofed emails still get delivered. The goal is p=reject. Here's how to get there without breaking legitimate mail.
Try our Email checker1. Spend 2-4 weeks on p=none
Collect DMARC aggregate reports (rua=) and identify every legitimate sender — your ESP transactional service marketing platform helpdesk etc. Authorize each via SPF includes or DKIM signing.
2. Move to p=quarantine with pct=10
Apply quarantine to only 10% of failing mail. Watch reports for a week. If you see legitimate mail in quarantine fix authentication for that sender.
3. Ramp pct to 100
Bump pct=25 then 50 then 100 over a few weeks. Each step re-check reports and fix any newly-broken senders.
4. Switch to p=reject
Once you're at quarantine pct=100 and reports show no legitimate mail failing change p=quarantine to p=reject. Spoofers will be blocked outright.
Want to verify your setup?
Run the check now