DMARC record
Publish a TXT record at_dmarc.<sending-domain> using the value Signal shows for the domain.
A record normally contains a version, policy, and aggregate-report destination.
Use the exact value generated for your project.
The example illustrates record shape and is not a substitute for the dashboard value.
Alignment
DMARC passes when an authenticated DKIM or SPF identifier aligns with the domain visible in the From header. A provider can authenticate a message but still fail DMARC if the domains do not align.Roll out policy
1
Inventory senders
Start with reporting and identify every legitimate service that sends as the domain.
2
Fix authentication
Configure aligned DKIM wherever possible and correct authorized SPF paths.
3
Review aggregate reports
Investigate unknown sources and recurring alignment failures.
4
Move to enforcement
Adopt
quarantine or reject only after legitimate traffic consistently aligns.
Use percentage controls if your policy process calls for a staged rollout.Policy values
Troubleshooting
- Publish only one DMARC TXT record at the policy host.
- Confirm the report mailbox can receive aggregate reports.
- Check From-domain alignment, not only raw SPF or DKIM pass.
- Avoid adding every reported source to SPF.
- Account for forwarded mail and third-party senders before enforcement.
Analyze reports
Import and investigate aggregate DMARC evidence in Signal.