DMARC
Short definition
DMARC combines SPF and DKIM results into a single policy that tells receiving servers what to do with failed mail.
DMARC, Domain-based Message Authentication, brings together the results of SPF and DKIM checks and applies a policy the domain owner sets: accept the message, quarantine it, or reject it outright.
It also sends the domain owner regular reports on who is sending mail using that domain and with what results, which is the most practical way to spot spoofing attempts early.
Without DMARC, SPF and DKIM are only recommendations, the receiving server is not obliged to act on them. DMARC turns those two checks into a binding rule.
The most common mistake is jumping straight to a reject policy without first monitoring, which can block legitimate mail that has not yet been fully verified and cause it to vanish silently. The right approach starts with a none policy purely to collect reports, moves to quarantine once nothing legitimate is being caught, and only reaches reject last.
Why it matters
A domain without DMARC leaves the door open to phishing and fake invoice emails, fraud attempts using the company name can spread unnoticed. Setting a policy directly protects the brand's reputation.
Illustrative example
A payment provider spotted, through its DMARC reports, that fake invoices reaching its customers were being sent by spoofing its own domain.
