Domain-based Message Authentication, Reporting and Conformance (DMARC)

DMARC is an email security tool that helps stop scammers from pretending to send emails from your domain. It works with two other email security checks (SPF and DKIM) to ensure that only approved senders can use your domain. This stops phishing attempts and gives people confidence that your emails are legitimate.

DMARC lets domain owners decide what should happen when an email fails authentication: should it be delivered anyway, sent to spam, or blocked completely?

It builds on SPF (which checks if an email comes from an approved server) and DKIM (which verifies the message hasn’t been altered in transit). When your DMARC policy is set up, receiving mail servers check incoming messages for SPF and DKIM alignment. If the message fails, your DMARC policy tells the server how to respond.

DMARC also provides detailed reports so organisations can see who’s sending emails on their behalf, both authorised and unauthorised senders.

Keep expanding your knowledge

GDMA Email Benchmark 2026: fewer peaks, steadier sending 
Email tracking pixels and consent: what European senders need to know in 2026
The overlooked opportunity with Lovable: how easy it is to choose GDPR-proof email sending.
What is the US CLOUD Act?
The inbox has changed. Email Marketers are playing catch-up – our take on the Litmus 2026 report
AI in the modern inbox: what’s happening?
Mailgun vs Spotler SendPro: Why European businesses are making the switch
SendGrid vs Spotler SendPro: Why European businesses are making the switch
How to build emails that work in dark mode
The AI Inbox: what is it and what do you need to take into account?