Spammers will often try to forge the "From" address in an email to deceive recipients and perform unlawful activities. Obviously mailbox providers want to prevent such emails landing in the inbox of their users, and email senders don't want their emails to be tampered with. The only way to achieve these goals, though, is by implementing domain authentication techniques.
DMARC (Domain-based Message Authentication Reporting and Conformance) is an authentication technique that uses the Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) to validate emails. DMARC allows a business to publish a policy that provides instructions to the receiving servers of mailbox providers on how to handle unauthenticated emails sent from their domain.
When you implement DMARC, there are three actions you can instruct the receiving server to perform when they receive unauthenticated emails from your domain.
Take no action
You can design a policy and set it as "p=none". When a receiving server identifies an unauthenticated email, it will accept it without taking any action.
Quarantine the email
You can design a policy and set it as "p=quarantine". When the receiving server identifies an unauthenticated email, it will accept the email and store it in the quarantine folder on the server. Only the server's administrators will be able to view these emails.
Reject the email
You can design a policy and set it as "p=reject". The policy will instruct the receiving server to reject unauthenticated email. You can learn more about the email that got rejected by analyzing the DMARC failure report.
How DMARC works
DMARC is dependent on two other email authentication techniques, SPF and DKIM. For an email to pass the DMARC validation, it must either pass the SPF authentication and alignment validation or DKIM authentication and alignment validation.
Step 1
You need to publish the DMARC policy that provides instructions to the receiving servers of mailbox providers on handling emails that violate the policy. The record may take 24 hours to get reflected.
Step 2
You need to authenticate your sender domain by implementing SPF and DKIM. If you send emails without implementing SPF and DKIM, your emails may bounce. After implementing SPF and DKIM, when you send emails, the receiving server of the mailbox provider will use the DNS to identify the DMARC record corresponding to the sender domain. The receiving server will perform the following actions:
- Validate the DKIM key.
- Verify whether the email was sent from an IP address that's listed in the SPF record.
- Verify whether the headers in the email message show proper domain alignment.
Step 3
The receiving server will apply the DMARC policy and carry out the instruction defined in the policy.
Step 4
The receiving server will send a report on how it handled the email to the reporting email address listed in the DMARC record.
Decoding the DMARC record
Here's a sample DMARC record
v - Indicates the version of DMARC that's being used.
p - Indicates the policy set by the business.
rua - Indicates the URI to which a consolidated report will be sent detailing the SPF and DKIM validation results, information about the sending and receiving domains, and the percentage of successful authentications.
ruf - Indicates the email address to which the detailed SPF/DKIM failure report will be sent.
pct - Indicates the percentage of emails on which the policy will be applied.
How to implement DMARC records
DMARC implementation consists of three steps which are described in more detail below:
- Validate your SPF and DKIM records
- Generate a DMARC record
- Add the record to your domain's DNS
Validate your SPF and DKIM records
You
need to verify if your SPF and DKIM records are authenticated and
properly aligned. Please remember that it is mandatory to set up SPF and
DKIM records for your domain to implement DMARC. If either SPF/ DKIM
record's authentication and alignment check fails then the DMARC test
will also automatically fail.
To check the SPF / DKIM alignment:
- For your SPF record, ensure that the "from address" and the "return-path address" match
- For your DKIM record, ensure that the "from address" and the "d" tag of the record match.
Generate a DMARC record
You can use any tool recommended listed by
DMARC.org to generate a new DMARC record.
Add DMARC record to your domain's DNS
The
final step is to add the DMARC record to the DNS server as a TXT
record. Each domain hosting provider has a different process for
completing this task. You can do this last step on your own or get your
domain hosting provider to help you.
Choose an email account to receive DMARC reports
You
must choose an email account to receive reports on the performance of
your email. We recommend that you use a distinct email account so that
the emails do not get lost in the flood of other emails you receive on a
regular basis. These reports will help you understand how your email is
performing and will assist you in changing the way you communicate with
your recipients.
Benefits of implementing DMARC
Implementing DMARC has the following benefits:
- Prevents fraudsters from using your sender domain to perform spoofing activities.
- Improves email deliverability as implementing DMARC will get you into the good books of mailbox providers and anti-spam service.
- It helps you monitor the emails you send and gives you control over how mailbox providers handle unauthenticated emails sent from your domain.
At Zoho Marketing Automation, we urge our users to implement SPF, DKIM, and DMARC, as it is the best way to safeguard your emails. Read
our help article to learn more about setting up the SPF and DKIM TXT records of your sender domain.