security / email authentication / dmarc
Email authentication

DMARC

DMARC tells receiving mail servers what to do with emails that fail authentication — and gives you visibility into who is sending mail using your domain.

Severity if missing
High
Category
Email authentication
Standard
RFC 7489

What it is

DMARC (Domain-based Message Authentication, Reporting and Conformance) builds on two older standards, SPF and DKIM. Those two check whether an email is authorized to use your domain — but on their own, they don't say what should happen when a message fails those checks.

DMARC fills that gap. It's a small record in your DNS that gives receiving servers a clear instruction: allow the message, send it to spam, or reject it outright.

Why it matters

Without a DMARC policy, anyone can send email that appears to come from your domain. Attackers use this for phishing — a fake invoice from "your company", a password reset that isn't real — and your customers have no way to tell it's forged.

The risk
A missing or p=none policy means spoofed emails are delivered normally. Your domain can be impersonated in phishing attacks against your own customers.

How Pentrawl checks it

Pentrawl looks up the _dmarc TXT record for your domain and reads its policy. We report a pass for p=reject, a warning for p=quarantine, and an issue for p=none or no record at all.

How to fix it

Add a DMARC record to your DNS as a TXT record on the _dmarc subdomain. Start with a monitoring policy, then tighten it once you've confirmed your legitimate mail passes.

Recommended
_dmarc.yourdomain.com. TXT "v=DMARC1; p=reject; rua=mailto:you@yourdomain.com"
Start here if unsure
_dmarc.yourdomain.com. TXT "v=DMARC1; p=none; rua=mailto:you@yourdomain.com"

Related checks

Check your domain's DMARC in seconds
Pentrawl scans this and 20+ other security checks in one automated pass.
Scan your website →