Skip to main content
DMARC tells receiving providers how to evaluate mail that uses your visible From domain. It builds on SPF and DKIM alignment and can request aggregate reports.

DMARC record

Publish a TXT record at _dmarc.<sending-domain> using the value Signal shows for the domain. A record normally contains a version, policy, and aggregate-report destination.
Use the exact value generated for your project. The example illustrates record shape and is not a substitute for the dashboard value.

Alignment

DMARC passes when an authenticated DKIM or SPF identifier aligns with the domain visible in the From header. A provider can authenticate a message but still fail DMARC if the domains do not align.

Roll out policy

1

Inventory senders

Start with reporting and identify every legitimate service that sends as the domain.
2

Fix authentication

Configure aligned DKIM wherever possible and correct authorized SPF paths.
3

Review aggregate reports

Investigate unknown sources and recurring alignment failures.
4

Move to enforcement

Adopt quarantine or reject only after legitimate traffic consistently aligns. Use percentage controls if your policy process calls for a staged rollout.

Policy values

Troubleshooting

  • Publish only one DMARC TXT record at the policy host.
  • Confirm the report mailbox can receive aggregate reports.
  • Check From-domain alignment, not only raw SPF or DKIM pass.
  • Avoid adding every reported source to SPF.
  • Account for forwarded mail and third-party senders before enforcement.

Analyze reports

Import and investigate aggregate DMARC evidence in Signal.