Trust

Your DMARC policy acts on forged email

trust.dmarc-policy-none

Why this matters

A DMARC policy of 'none' asks mailbox providers to report forgeries and then deliver them anyway. That is the right place to begin — the reports are how you find out which services legitimately send mail as you — but on its own it stops nothing. Most domains that publish DMARC never move past it, and monitoring is easily mistaken for protection.

Who fixes it

You can, usually

Roughly how long

A few weeks of reading reports, then a one-line DNS change. The waiting is the work.

Care needed

Test before and after

How to fix it

Read your DMARC reports until every legitimate sender is accounted for by SPF or DKIM — there is nearly always one you had forgotten, an old newsletter tool or a CRM. Then move the policy to `p=quarantine`, and to `p=reject` once quarantine is quiet. Do not go straight to `reject`: that is how a business stops its own invoices being delivered.

How we score it

Failing this check takes up to 8 points off your trust score. It is a fact about your site rather than a measurement, so it reads the same on every scan until you change something.

Does your site pass this one?

This check runs on every scan, along with the other 106. Free, no account, and you see the evidence for each result.

Check my site

Other trust checks

See all 107 checks