Complete SPF record setup guide, including syntax explanation and best practices
Configure DANE for SMTP with TLSA records to enforce secure delivery
Set up MTA-STS policy with Cloudflare for secure SMTP delivery
DMARC (Domain-based Message Authentication, Reporting, and Conformance) lets you set a policy telling receivers how to handle messages that fail SPF and/or DKIM alignment, and it provides reporting so you can monitor sources. With Cloudflare DNS, publishing DMARC is straightforward, but getting alignment right takes care. This guide covers policy design, record publishing, and validation.
p=none (monitor), p=quarantine, or p=reject.rua) and forensic (ruf), sent to your specified addresses.Begin with monitoring to discover all legitimate senders before enforcement:
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-aggregate@example.com; ruf=mailto:dmarc-forensic@example.com; fo=1; adkim=s; aspf=s"
adkim=s and aspf=s require strict alignment, reducing spoof risk.fo=1 requests failure reports; receivers vary in support._dmarc with your policy value.Ensure at least one of SPF or DKIM aligns with the visible From: domain:
d=example.com signature that matches the From: domain.Many domains use multiple providers (transactional, marketing, support). Steps:
d= whenever possible.Authentication-Results, DKIM-Signature, Received-SPF.p=quarantine and then p=reject once confident.sp= tag to set subdomain policy, or publish per-subdomain records.With Cloudflare DNS and a staged rollout, DMARC improves trust and visibility across your email ecosystem while minimizing disruption.