DMARC in 5 minutes for people who ship fast
It's the single most common line in a shakedown email, and it's one of the easiest things on the whole internet to fix. Here's what DMARC actually does, the exact record to paste, and how to turn it on without nuking your own email.
If you own a domain and you've never touched your email DNS, here's the uncomfortable truth: right now, a stranger can almost certainly send email that says it's from you — to your customers, your users, your own boss — and most inboxes will wave it through.
That's not a bug in your app. It's a default. Email was built in an era of trust, and “who is this really from?” was bolted on later, as three DNS records you have to opt into. Miss the third one and you're spoofable. Which is exactly why “no DMARC record” is the line we see screenshotted in shakedown emails more than any other. It's free to find and free to fix — the shakedown just counts on you not knowing that.
The three records, in plain English
You don't need to become an email admin. You just need to know what each record is claiming so the fix makes sense.
SPF — who's allowed to send
A list of the servers permitted to send mail for your domain (“Google and my newsletter tool, nobody else”). A receiving inbox checks the sending server against your list. If you use Google Workspace or Microsoft 365, they hand you the exact SPF value to publish.
DKIM — a tamper-proof signature
Your provider cryptographically signs outgoing mail, and the matching public key lives in your DNS. The receiver verifies the signature — so they know the message really came from your setup and wasn't forged or altered in transit. This is also turned on in your email provider's admin panel, not by hand.
DMARC — the policy that ties it together
Here's the one everyone forgets. DMARC tells inboxes what to dowhen a message claiming to be from you fails SPF and DKIM: nothing, quarantine to spam, or reject outright. No DMARC record means the answer is effectively “shrug, deliver it anyway.” That's the hole.
SPF and DKIM prove identity. DMARC is the bouncer who actually acts on it. You can have the first two and still be spoofable if the third isn't there — which is the situation most fast-shipped domains are in.
The record you paste
DMARC is a single TXT record at a fixed hostname. In your DNS provider (Cloudflare, Namecheap, Route 53 — wherever your domain lives), add a TXT record like this:
That's the whole thing. Decoded:
- v=DMARC1 — this is a DMARC record. Always first.
- p=none — the policy. Start at
noneso nothing gets blocked yet — you're only watching. More on this in a second. - rua=mailto:…— where to send the daily aggregate reports of who's sending as you. Point it at an inbox you actually check.
Why you don't jump straight to p=reject
It's tempting to slam the door with p=reject on day one. Don't. If your SPF or DKIM isn't set up quite right — or you forgot that your invoicing tool and your CRM both send on your behalf — you'll start silently bouncing your own legitimate email. That's a worse Monday than the shakedown was.
Walk it up in three steps, over a week or two:
- 1
p=none — watch.
Publish the record above. Nothing is blocked. The dailyruareports show you every service sending as your domain — including the ones you forgot about. Fix SPF/DKIM until only your senders pass. - 2
p=quarantine — send failures to spam.
Once your real mail is passing cleanly, changep=nonetop=quarantine. Now spoofed mail lands in spam instead of the inbox. Watch the reports for a few more days. - 3
p=reject — slam the door.
Flip top=rejectand forged mail is refused outright, before it ever reaches anyone. This is the end state you want. Now “anyone can email as you” is simply false.
The 5-minute version
If you have five minutes right now and want to stop being trivially spoofable today:
- Turn on SPF and DKIMfrom your email provider's admin panel (Google Workspace and Microsoft 365 both have a one-page guide; it's copy-paste).
- Add the _dmarc TXT record above with
p=none. - Put a reminder to come back in a week, read one
ruareport, and step up toquarantine, thenreject.
That's it. No new tools, no budget, no security team. One TXT record and a follow-up. The record a shakedown artist was going to screenshot and demand $500 for now comes back clean.
The whole racket runs on the gap between “this sounds terrifying” and “this is one line of DNS.” DMARC is the purest example of that gap. Close it and you've taken their best line away.
Not sure if your DMARC (or SPF, or DKIM) is actually set right? Find out in about 20 seconds.
Scan your site free →