Skip to content

Configure DMARC policies with MailOut

Last updated on

A DMARC policy is used to reduce fraudulent behaviour using email. There are a broad range of parameter settings to harden your DNS setup using DMARC.

In general, your DMARC record must start with the attribute “v=DMARC1”.

To successfully validate the DNS Records for your sending domain with STACKIT MailOut, you must set the “p” attribute to clarify the behaviour for your sending domain.

In addition, you can also define the behaviour for subdomains with the attribute “sp” of the DMARC record.

Customers are responsible to set an appropriate DMARC policy on their own. STACKIT MailOut will accept settings “none”, “quarantine” and “reject” for parameter “p” and “sp”. The “none” mode is recommended for testing purposes only.

A recommended DMARC DNS record should at least look like this:

Once you are completely confident that your p=quarantine rollout is working flawlessly, it’s time to transition to p=reject. Making this move unlocks the highest tier of email security, providing the absolute strongest defense against domain spoofing and phishing attacks.