Skip to main content
email·digit

Move DMARC from p=none to p=reject without breaking mail

Move DMARC to p=reject in stages, not in one edit. Stay at p=none until your reports show every legitimate sender passing aligned, then quarantine a small share of failing mail, raise it, and only then reject. Give each step a couple of weeks of report data before taking the next one.

Why the jump to reject breaks things

p=reject tells every receiving server to refuse mail that uses your domain and fails DMARC. That is the point: it stops people spoofing you. The trouble is that it also refuses your own mail from any sender you forgot to set up, such as the billing tool, the old CRM, the help desk, or the agency that sends the newsletter.

The two enforcing policies fail very differently:

PolicyWhat happens to failing mailHow you find out about a mistake
p=noneDelivered as normal. You only get reports.In the reports.
p=quarantineUsually sent to the spam folder.Someone eventually finds it in spam.
p=rejectRefused at the door. It never arrives.Often days later, through a customer complaint.

That is why the usual advice is a ramp: each step exposes a little more failing mail, and the reports tell you whether any of it was yours before the stakes go up.

A staged path

The pct tag sets what share of failing mail the policy applies to. A common ladder looks like this:

v=DMARC1; p=none
v=DMARC1; p=quarantine; pct=10
v=DMARC1; p=quarantine; pct=50
v=DMARC1; p=quarantine; pct=100
v=DMARC1; p=reject; pct=25
v=DMARC1; p=reject; pct=100

Before each step up, check three things in your aggregate reports:

  1. Alignment across all your mail. Nearly all of the mail using your domain should pass SPF or DKIM in a way that matches your From: domain. If you have not read a report before, start with How to read a DMARC report.
  2. Every source that fails. Each failing IP is either a sender you need to set up, or someone you are happy to block. Know which before you tighten. For telling the two apart, see Unknown IPs in your DMARC report.
  3. Enough time. Some senders only run monthly, like invoices or a quarterly newsletter. A step that looked clean for three days may not have seen them yet.

One note on pct: the 2026 update to the DMARC standard (RFC 9989) replaces it with a testing flag. A receiver that has adopted the update may ignore pct and apply the policy to all failing mail rather than a share, so treat the percentage steps as a gentler slope, not a promise.

Share of failing mail each DMARC step acts onSix steps. p=none acts on no failing mail, reports only. Quarantine at 10, 50 and 100 percent sends that share to spam. Reject at 25 percent refuses a quarter and quarantines the rest. Reject at 100 percent refuses all failing mail.Share of failing mailQuarantinedRefused50%100%reportsnone10%quarantinepct=1050%quarantinepct=50100%quarantinepct=10025% refusedrejectpct=25100%rejectpct=100
Under p=reject with pct=25, the failing mail outside the 25% is quarantined instead. A receiver that follows the 2026 update may ignore pct.

How Email Digit gates each step

Every domain you add as a managed sending domain starts at p=none and climbs the same six steps shown above. Moving up is one click, and the button refuses to move until three things are true:

  • the domain is verified,
  • it has spent at least 14 days at its current step, and
  • the DMARC reports for the last 30 days show at least 95% of messages aligned.

If no reports have reached Email Digit for the domain, it says “No DMARC reports received yet, so alignment can’t be verified” instead of guessing. When it refuses, it tells you which condition failed, for example how many more days to wait. The screen that shows that verdict and the check that enforces it use the same calculation, so the page can never say “wait 11 more days” while the button moves anyway.

On a managed domain, Email Digit updates the DMARC record for you when you click, so there is no DNS edit. If your domain uses the older setup where you published the DMARC record yourself, the domain returns to pending until you publish the new value.

The extra warning before reject

Quarantine mistakes are recoverable; reject mistakes are silent. So the step from quarantine into reject asks for its own confirmation, and the warning is built from your report data over the last 30 days:

  • how many sending sources were seen,
  • how many of them are failing alignment, and
  • which ones sent the most failing mail, with their message counts.

A warning that says a source at 198.51.100.7 sent 412 failing messages is one you can act on. A generic “are you sure?” is one you click through. It is advisory: if you have genuinely retired that sender, you can confirm and go ahead.

What it does not do

  • It never advances by itself. Every step is your click. Email Digit offers the next step when the evidence supports it; it does not take it for you.
  • It depends on reports reaching it. The alignment figure comes from aggregate reports that have arrived for that domain. Without them, the button stays put and tells you why.
  • It cannot fix a failing sender. It can name one. Setting up SPF or DKIM for that service, or retiring it, is still a job for whoever owns it.

Treat p=reject as a ramp you earn with evidence, not a date on a calendar. To see what your own reports say today, paste one into the free DMARC report analyser.

Sources

  1. RFC 7489: DMARC, section 6.3
  2. RFC 9989: DMARC, the 2026 revision
Share this guideShare on XShare on LinkedIn