DMARC p=none: What It Means and How to Fix It
If BadgerScan flagged your domain with "DMARC p=none", you have a DMARC record, but it is set to monitor only. Receiving servers still deliver mail that fails your checks, so your domain can still be spoofed. Here is how to move to real enforcement without breaking your legitimate email.
One free scan, no login. This check runs alongside DNS, email, TLS, headers, exposed files and known CVEs.
What p=none actually does
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do when a message claiming to be from your domain fails SPF and DKIM. The policy is set by the p= tag, and it takes one of three values: none, quarantine, or reject.
p=none is the monitoring-only setting. It asks receivers to send you reports about mail using your domain, but it explicitly tells them to deliver messages that fail authentication anyway. In other words, a stranger can still put your domain in the From address and land in your customers' inboxes. That is why BadgerScan treats p=none as unprotected: you have taken the first step, but the door is still open (Cloudflare, What is a DMARC record?).
p=quarantine tells receivers to treat failing mail as suspicious (usually routing it to spam), and p=reject tells them to refuse it outright. Reject is the goal: it is the only policy that actually stops spoofing (RFC 7489, section 6.3).
Why it is worth fixing
A spoofable domain is a common first move in phishing and invoice-fraud scams: an attacker emails your customers or staff as you, and there is nothing at the receiving end telling the server to reject it. Small businesses are hit hardest by these attacks, and email impersonation is one of the cheapest ways in.
Moving to enforcement also protects your deliverability and reputation. Major mailbox providers increasingly expect a real DMARC policy, and a domain stuck at p=none looks unfinished to them.
How to fix it, step by step
The safe path is to confirm your legitimate mail passes authentication first, then tighten the policy in stages so you never black-hole your own email:
- Confirm SPF and DKIM are set up and passing for every service that sends mail as you (your mail host, plus any newsletter, CRM, invoicing or support tools). If either is missing, fix that before you enforce.
- Add a reporting address so you can see who is sending as you. In your DMARC record, set
rua=mailto:[email protected]. Leave the policy at p=none for a week or two and read the aggregate reports to spot any legitimate sender that is failing. - Once your real senders all pass, move to
p=quarantine. Failing mail now goes to spam instead of the inbox. Watch your reports for another week to be sure nothing legitimate is caught. - Finally, move to
p=reject. A complete record looks like:v=DMARC1; p=reject; rua=mailto:[email protected]. This is the setting that actually blocks spoofing. - Publish the change as a single TXT record at
_dmarc.yourdomain.com. There should be only one DMARC record; a second one is an error and receivers will ignore both.
The one thing not to do
Do not jump straight to p=reject before you have confirmed your legitimate senders pass SPF or DKIM. If a real sender is failing and you set reject, that mail stops being delivered, which usually shows up as your own invoices or newsletters silently vanishing. The staged rollout above exists precisely to avoid that. If you are not sure which of your services send mail, the aggregate reports from the p=none stage will tell you before you tighten anything.
Check your DMARC policy in under a minute
Run the free BadgerScan scan to see your current DMARC, SPF and DKIM setup, whether your domain can still be spoofed, and the exact next step. No login, no test emails, just a plain-English read.
Run a free security scanFrequently asked questions
Is p=none better than having no DMARC at all?
Slightly, because you at least get reports about who is sending as your domain, and some receivers weigh a published record. But p=none does not block spoofing, so it should be a short first step on the way to p=quarantine and then p=reject, not a resting place.
Will moving to p=reject break my email?
Only if a legitimate sender is failing SPF and DKIM when you switch. That is why you confirm every real sender passes first, using the reports from the p=none and p=quarantine stages. Done in that order, enforcement does not affect mail you actually send.
How long should I stay at each stage?
A common rhythm is one to two weeks at p=none to gather reports, then one to two weeks at p=quarantine, then p=reject. If your reports are clean sooner and you know all your senders, you can move faster.
How do I check my DMARC policy?
BadgerScan reads your SPF, DKIM and DMARC records as part of one free external scan and tells you, in plain English, whether your domain is enforced or still spoofable. It is passive and read-only: it never sends test emails or logs in.
Sources
More from CyberBadger
BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.
Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.