ZeroSpams

DMARC setup, monitoring and reporting

DMARC is what actually stops criminals from sending email in your name, and it tells you, every day, who is sending email as your domain. Most businesses either don’t have it, or have it in "monitor only" mode with nobody reading the reports.

Updated · 2 min read · By the ZeroSpams team

The short answer

DMARC is a DNS record that tells receivers what to do with emails that fail SPF and DKIM checks for your domain (nothing, send them to spam, or reject them) and asks them to send you daily reports [1]. Gmail and Outlook require at least a monitoring policy for larger senders [2][3]. We set it up, read the reports for you, fix the gaps, and move you to real protection.

What’s included

  • A DMARC record with a reporting address, starting at p=none (monitor only).
  • Report collection and analysis: the daily XML reports turned into a readable list of who sends email as your domain.
  • Fixing the legitimate senders that fail, such as a CRM, invoicing or marketing tool.
  • A step-by-step move to p=quarantine and then p=reject, when it’s safe.
  • DMARC for subdomains and for domains that never send email.
  • Ongoing monitoring (optional): a monthly summary, and alerts when something new appears.

How we do it

  1. Publish DMARC in monitoring mode with reporting switched on.
  2. Collect two to four weeks of reports from Gmail, Outlook, Yahoo and others.
  3. Identify every source: your real senders, forwarders, and anyone forging your domain.
  4. Fix SPF and DKIM for every legitimate sender until they align.
  5. Enforce: quarantine first, then reject, watching the reports at each step.

Reading the reports is the hard part

DMARC aggregate reports arrive as compressed XML files, usually daily, from every large mailbox provider that received email claiming to be from you [1]. They list the sending IP addresses, how many messages each sent, and whether SPF and DKIM passed. Unread, they’re useless; read, they show you exactly which of your services are misconfigured and whether anyone is impersonating you. We turn them into a short, plain summary.

Why "p=none" isn’t protection

A monitoring-only policy meets the minimum requirement for larger senders [2][3], but it doesn’t stop anyone forging your domain: it only reports them. Real protection comes from p=quarantine or p=reject, which is where we take you once every legitimate sender passes. See also phishing and spoofing protection.

Common questions

How long does it take to reach p=reject?

Usually four to eight weeks for a small business: time to collect reports, fix every legitimate sender, and move through quarantine safely. Complex setups with many tools take longer.

Will DMARC block my own emails?

Not if it’s done in stages. Monitoring mode blocks nothing; we only tighten the policy when the reports show all your real email passes.

Do you offer ongoing DMARC monitoring?

Yes, as an option: a monthly summary of who sent email as your domain, and alerts when a new source appears or failures rise.

Sources

Numbers in this guide come from these studies and publications. Links open the original.

  1. RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)IETF, 2015
  2. Email sender guidelines FAQGoogle Workspace Admin Help (Gmail)Requirements for senders of 5,000+ messages a day to Gmail since February 2024; stricter enforcement, including rejections, since November 2025.
  3. Strengthening Email Ecosystem: Outlook’s New Requirements for High-Volume SendersMicrosoft Defender for Office 365 blog, Microsoft Tech Community, 2025Since 5 May 2025: SPF, DKIM and DMARC required for domains sending 5,000+ emails a day to Outlook.com, Hotmail and Live.