DMARC policy not enabled
What the DMARC policy not enabled warning means, whether p=none affects delivery, and the safe order to move to quarantine or reject.
On this page
- What the warning means
- Is it hurting your email today?
- What large senders publish (live DNS)
- How to fix it without blocking your own mail
- 1. Publish p=none with a reporting address
- 2. Read the reports and fix your senders
- 3. Move to quarantine
- 4. Consider reject
- Two record mistakes to rule out
- Check the fix
- Sources
The "DMARC policy not enabled" warning means your domain's DMARC record does not ask receivers to quarantine or reject mail that fails authentication; MXToolbox's fix (opens in a new tab) is to set one of those two policies. The possible policy values (opens in a new tab) are none, quarantine and reject, and under none the domain owner offers no expression of preference. Start at p=none with reports, fix the senders they show failing, then move to quarantine and, when your reports support it, to reject.
What the warning means
MXToolbox (opens in a new tab) raises this warning when a domain's DMARC record is not protected against phishing and spoofing, and it advises evaluating your DMARC reports before you set quarantine or reject, so legitimate senders don't run into delivery problems. DemiSignal's check flags a policy of none too, along with a missing record, no reporting address, a policy that covers only part of your email, and subdomains left at none.
RFC 9989 (opens in a new tab), which obsoletes RFC 7489, defines DMARC (Domain-based Message Authentication, Reporting, and Conformance). DMARC builds on Sender Policy Framework (SPF) (opens in a new tab), which lets a domain owner publish the hosts allowed to use its domain in the MAIL FROM address, and DomainKeys Identified Mail (DKIM) (opens in a new tab), which signs messages so receivers can confirm the signed content has not changed (RFC 9989 section 1 (opens in a new tab)). To pass DMARC, a message needs an SPF or DKIM pass for a domain aligned with the domain in its From address; a message with neither fails (section 5.3 (opens in a new tab)).
RFC 9989 calls it "Monitoring Mode" when the policy for a domain and all its subdomains is p=none (section 3.2.12 (opens in a new tab)), and Enforcement (opens in a new tab) when the policy for the domain and all its subdomains is not p=none. A record can give subdomains their own policy with the sp tag (section 4.7 (opens in a new tab)), so check both before calling a whole domain monitored or enforced.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
Is it hurting your email today?
A p=none policy asks receivers for no DMARC-specific action. Microsoft (opens in a new tab) describes it as no suggested action for messages that fail DMARC, with the outcome left to the receiving system's own protection features, and as a value for testing and tuning a policy. A discovered p=none policy must not change a receiver's existing mail handling (RFC 9989 section 5.4 (opens in a new tab)). Other filtering still applies, so p=none does not guarantee delivery or inbox placement.
Gmail's and Yahoo's sender requirements accept it. Since February 1, 2024, Gmail (opens in a new tab) has required senders of more than 5,000 messages a day to Gmail accounts to set up DMARC, and the enforcement policy can be set to none. Yahoo (opens in a new tab) requires bulk senders to publish a valid DMARC policy of at least p=none.
Enforcement asks receivers to handle failing mail differently. With quarantine you tell them you consider such mail suspicious; with reject, that you consider the failures a clear sign the use of your domain is not valid (section 4.7 (opens in a new tab)). Receivers make the final decision under their own policies, and may accept failing mail even at p=reject. Microsoft describes quarantined mail as possibly quarantined as spam, delivered to the Junk Email folder, or delivered to the Inbox with a marker added, and rejected mail as typically discarded. For inbound mail with Honor DMARC record policy on, Microsoft 365 rejects p=reject failures during SMTP with 550 5.7.1.
What large senders publish (live DNS)
| Domain | _dmarc TXT record |
|---|---|
gmail.com |
v=DMARC1; p=none; sp=quarantine; rua=mailto:[email protected] |
outlook.com |
v=DMARC1; p=none; sp=quarantine; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1 |
google.com |
v=DMARC1; p=reject; rua=mailto:[email protected] |
microsoft.com |
v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; fo=1 |
yahoo.com |
v=DMARC1; p=reject; pct=100; rua=mailto:[email protected]; ruf=mailto:[email protected]; |
gmail.com and outlook.com pair p=none with sp=quarantine: the sp policy applies to their existing subdomains, not to the domain itself (RFC 9989 section 4.7 (opens in a new tab)). Treat these records as examples, not a template to copy.
How to fix it without blocking your own mail
Publish the policy as a TXT (text) record in the Domain Name System (DNS) (opens in a new tab), at _dmarc in front of your domain (RFC 9989 section 4.1 (opens in a new tab)): receivers start policy discovery (opens in a new tab) with a query at that name.
1. Publish p=none with a reporting address
The rua tag lists the addresses that receive aggregate reports, and without it receivers must not send you any (RFC 9989 section 4.7 (opens in a new tab)). Domain owners usually start at p=none with a rua address pointing to a mailbox set up for reports (RFC 9989 section 5.1.4 (opens in a new tab)). Yahoo (opens in a new tab) strongly recommends a properly set up rua address for monitoring during initial setup.
This is the record DemiSignal's DMARC generator writes for this step. Replace [email protected] with a working mailbox or your reporting service's address before publishing:
v=DMARC1; p=none; rua=mailto:[email protected]
2. Read the reports and fix your senders
Before you move to enforcement, any legitimate mail stream that fails authentication or alignment must be fixed (RFC 9989 section 5.1.6 (opens in a new tab)). Depending on how often you send, that can take many months of reports (section 5.1.7 (opens in a new tab)), so wait until the reports cover your normal sending cycles. Reports come only from receivers that send them; some opt out (section 5.3 (opens in a new tab)).
3. Move to quarantine
Once your reports show your legitimate senders pass, change p to quarantine:
v=DMARC1; p=quarantine; rua=mailto:[email protected]
This asks receivers to treat mail that still fails DMARC as suspicious; what they do with it depends on the receiving system (Microsoft (opens in a new tab)).
4. Consider reject
When reports covering your normal sending cycles show your legitimate senders pass authentication and alignment, consider reject:
v=DMARC1; p=reject; rua=mailto:[email protected]
This asks receiving servers to reject failing mail; they still make the final decision under their own policies (RFC 9989 section 5.4 (opens in a new tab)).
Two cautions from RFC 9989 section 7.4 (opens in a new tab). Mail relayed through forwarding addresses will most likely fail SPF, while DKIM signatures generally remain valid, so a domain at p=reject must sign its mail with DKIM rather than rely on SPF alone. And a domain whose users post to mailing lists should not publish p=reject; if it still wants to, it should first spend at least a month at p=none and an equally long period at p=quarantine, comparing the results.
Two record mistakes to rule out
Publish exactly one DMARC record: if a lookup returns more than one, RFC 9989 (opens in a new tab) discards all of them. A record without a valid p tag but with a valid rua address is treated as p=none (section 4.10.1 (opens in a new tab)).
Check the fix
After you edit DNS, run DemiSignal's check: it checks your SPF, DKIM and DMARC records and needs no account. The DMARC record generator builds the record one step at a time, starting with monitoring and moving to enforcement once your reports show your real senders pass, and it saves nothing you enter.
Sources
- MXToolbox: DMARC Policy Not Enabled (opens in a new tab)
- RFC 9989 (RFC Editor information page) (opens in a new tab)
- RFC 9989 section 1: Introduction (opens in a new tab)
- RFC 9989 section 3.2.9: Enforcement (opens in a new tab)
- RFC 9989 section 3.2.12: Monitoring Mode (opens in a new tab)
- RFC 9989 section 4.7: DMARC Policy Record Format (opens in a new tab)
- RFC 9989 section 4.1: DMARC Basics (opens in a new tab)
- RFC 9989 section 4.10: DNS Tree Walk (opens in a new tab)
- RFC 9989 section 4.10.1: DMARC Policy Discovery (opens in a new tab)
- RFC 9989 section 5.1.4: Publish a DMARC Policy Record (opens in a new tab)
- RFC 9989 section 5.1.6: Remediate Unaligned or Unauthenticated Mail Streams (opens in a new tab)
- RFC 9989 section 5.1.7: Decide Whether to Update Domain Owner Assessment Policy (opens in a new tab)
- RFC 9989 section 5.3: Mail Receiver Actions (opens in a new tab)
- RFC 9989 section 5.4: Policy Enforcement Considerations (opens in a new tab)
- RFC 9989 section 7.4: Interoperability Considerations (opens in a new tab)
- RFC 7208: Sender Policy Framework (SPF), section 1 (opens in a new tab)
- RFC 6376: DomainKeys Identified Mail (DKIM) Signatures, section 1 (opens in a new tab)
- Google: Email sender guidelines (opens in a new tab)
- Google Workspace: About TXT records (opens in a new tab)
- Yahoo: Sender best practices (opens in a new tab)
- Microsoft: Set up DMARC to validate email in Microsoft 365 (opens in a new tab)
- DemiSignal: SPF, DKIM and DMARC check
- DemiSignal: DMARC record generator
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
What does "DMARC policy not enabled" mean?
Your DMARC record does not ask receivers to quarantine or reject mail that fails authentication. RFC 9989 calls p=none for a domain and all its subdomains Monitoring Mode.
Does p=none hurt my email delivery?
A policy of p=none asks for no DMARC-specific action. Other filtering still applies, so it does not guarantee delivery or inbox placement. Gmail and Yahoo accept p=none for their DMARC requirement.
What is the safe order to reach p=reject?
Publish p=none with a working rua reporting address. Review reports across your normal sending cycles and fix legitimate authentication or alignment failures. Then consider quarantine and reject, accounting for forwarded mail and mailing lists.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.