FM Field Manual smhansen.dev

FM 8-03 Chapter 8 · Email and identity

DMARC record

Explain and build v=DMARC1 policy records, with an optional DNS over HTTPS lookup.

Network Sends data to cloudflare-dns.com, dns.google: the _dmarc name you look up, only when you press Look up. Only when you press the button.

Mode
Resolver

Look up sends GET https://cloudflare-dns.com/dns-query?name=_dmarc.example.com&type=TXT. Nothing is sent before you press it.

v=Version
DMARC1 Marks this TXT record as a DMARC policy.
p=Policy for the domain
quarantine Mail that fails DMARC for this domain: treat failing mail as suspicious, usually deliver it to spam.
rua=Aggregate report addresses
mailto:[email protected] Daily XML summaries of who sends mail as this domain go here.
adkim=DKIM alignment mode
s Strict: the DKIM d= domain must equal the From: domain exactly.
Effective policy
domain quarantine, subdomains quarantine, non-existent quarantine
Alignment
DKIM strict, SPF relaxed

DMARC passes when SPF or DKIM passes for a domain that matches the From: address (aligned). The record lives in TXT at _dmarc.<domain>. Tags marked DMARCbis come from the successor draft to RFC 7489 (np= also from RFC 9091); older receivers ignore them. DMARCbis drops pct, rf and ri.

  • No entry in this manual matches “”.

↑ ↓ move · Enter open · Esc close