DMARC policy
Generated for you, tightened by you.

Every domain you add gets a starter record at p=none, printed to copy or written by a sync. The DMARC tool builds the stricter one when you want it.

In short

What is a DMARC record?

SPF and DKIM let a receiver check that mail really comes from your domain. DMARC is a TXT record at _dmarc.yourdomain.com that says what to do with mail that fails both: deliver it anyway, file it as spam, or refuse it.

How it works

A starter record at p=none

Each domain's DMARC tab prints the record to copy into your DNS, or a sync writes it for you.

A sync replaces what is there

Any policy already at _dmarc is written over with the starter, because two records there count as none. Copy a tuned one somewhere first.

The tool builds the next one

It reads what your domain publishes today and opens one step on, quarantine after none and reject after quarantine, then warns on five choices as you build.

The tags in a record

Only v and p are required.

p=noneChange nothingp=quarantineFile failures as spamp=rejectRefuse failures outrightruaWhere daily reports gorufForensic reports, rarely sentpctShare of failures policed

What you get

In the product today

One per domain

Generated as _dmarc.yourdomain.com for every domain you add.

Its own tab

Kept out of the delivery checklist, because the policy is yours.

Linked to the tool

Once _dmarc holds anything, even a broken record, the tab links to the tool.

Good practice

Getting the most out of it

  1. 01

    Start at none

    Leave the starter alone until you know what sends as your domain.

  2. 02

    Add a report address

    Put a rua on the record, or nothing tells you what a stricter policy would break.

  3. 03

    Move one step

    None to quarantine, then reject, with a few weeks of reports read in between.

Where it stands

Good to know

Aggregate reports
The starter requests none, and nothing in OpenEmail unpacks them. Add a rua and the daily compressed XML goes to that address.

Questions

Asked often

Keep going

Works well with

Verified sender

A mark beside the sender when the sending domain’s published records line up.

Phishing & spam filtering

Mail the sending domain itself disowns lands in Spam rather than the inbox.

Multiple domains

Point several domains at one inbox, subdomains included.

Start

Your domain,
your mail.

Point a domain at OpenEmail and read it in a mailbox built around it. The free plan covers one domain.

Your inbox,
on your own terms.

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

OpenEmail

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

© 2026 OpenEmail. All rights reserved.