CrowWake

← All guides

What is DMARC? The policy that stops spoofing

DMARC is the rulebook on top of SPF and DKIM: if a message fails authentication, should receivers quarantine it, reject it, or just watch?

US search interest: “dmarc” ~9.9k/mo · “dmarc checker” ~6.6k/mo (DataForSEO)—highest demand topic we cover.

What CrowWake checks

We read TXT at _dmarc.yourdomain for v=DMARC1. Missing record = fail. A policy of p=none is allowed but flagged as warn—you are monitoring without blocking spoofed mail yet.

Why it matters

Phishers love sending as [email protected]. DMARC is how brands tell the world “if it is not really us, don’t trust it.” Search demand for DMARC dwarfs most other email-auth terms—operators already know this is the wedge.

What “good enough” looks like

Start with p=none plus rua reporting while you inventory senders. Move toward p=quarantine or p=reject once legitimate mail passes SPF/DKIM alignment. CrowWake’s job in v1 is health of the DNS record—not parsing XML reports.

If CrowWake crows

No DMARC → publish a minimal record. Stuck on p=none forever → plan a move to stronger policy once senders are clean. Broken TXT syntax → fix quoting/spaces in DNS.

Watch this on CrowWake

Add the domain, leave the boxes checked, and the flock will crow when this drifts.

Start free