
Is "Dee Mark" the Newest Country Music Sensation? No Clue — But Say Hello to DMARC for Your Emails, Not Dee Mark.
Is "Dee Mark" the newest country music sensation?
No clue. Never heard of her. But say hello to DMARC for your emails, not Dee Mark.
And before we go any further — we owe you an apology. We had this post ready to go for days. Written, fact-checked, sitting in the queue. What held it up wasn't the DMARC content. It was us, staring at a blank line, trying to come up with a headline pun as good as "sun tan lotion" or "Who is The Kim." We're not entirely sure we succeeded. But we stand behind the sun tan lotion one. That was a good one.
Okay. Onto the actual subject.
That's Part 3 of our four-part series on email security. Part 1 covered SPF — the guest list that decides which servers are allowed to send email as you. Part 2 covered DKIM — the digital signature that proves nobody tampered with the message on the way to the inbox. Both are useful on their own. Neither one actually does anything with the information it finds. That's where DMARC comes in.
What DMARC actually is
Picture a bouncer standing at the door of a club. Two people show up claiming to be on the list. The bouncer checks the guest list — that's SPF, confirming the sender is who they say they are. The bouncer also checks that nobody swapped out their wristband on the way in — that's DKIM, confirming nothing was altered in transit.
But here's the thing: neither the guest list nor the wristband check actually decides what happens next. That's the bouncer's call. Let them in? Send them around back to wait? Turn them away at the door?
DMARC is the bouncer.
It doesn't do any authentication of its own. Instead, it looks at what SPF and DKIM already found and tells the receiving mail server what to do about it:
- Do nothing — let it through and just take notes (p=none)
- Quarantine it — send it to spam instead of the inbox (p=quarantine)
- Reject it outright — never let it reach the recipient at all (p=reject)
Without DMARC, SPF and DKIM can fail all day and nothing actually happens as a result — receiving servers are left to make their own judgment call, inconsistently, mailbox by mailbox. DMARC is what turns "we noticed something's off" into "here's what to actually do about it."
Do you need to worry about this?
If your business email runs through Microsoft 365, Google Workspace, or a similar provider, DMARC isn't automatic just because SPF and DKIM are set up. It's a separate DNS record you (or whoever manages your domain) has to publish on purpose. A lot of domains have SPF and DKIM configured correctly and still have no DMARC record at all — which means all that setup work isn't being enforced by anything.
There's also a middle ground worth knowing about: a lot of domains publish DMARC at p=none. That's not nothing — it means you're collecting data on what's passing and failing — but it's not protection either. Nothing gets blocked. If someone's spoofing your domain, p=none will quietly log it and let it happen anyway.
What happens if you skip it (or leave it at "none")
Without an enforced DMARC policy, there's nothing stopping someone from sending an email that looks like it's from your business — your domain, your name — straight into a customer's or vendor's inbox, even if it fails every authentication check you've put in place. Best case, it lands in spam and nobody notices. Worst case, it looks legitimate enough that someone acts on it — wires money, hands over credentials, opens something they shouldn't. That's the scenario SPF and DKIM alone can't fully prevent, because nothing was actually enforcing what to do when they failed.
The bottom line
SPF checks who's allowed to send. DKIM checks that nothing was altered along the way. DMARC is what finally puts the two of them to work together — turning two separate checks into one enforced policy. Together, all three are what separates "we have some email security stuff configured" from "our domain is actually protected."
There's still one more piece to this series — the lesser-known technologies that go beyond the basics, the kind of thing that separates "protected" from genuinely polished. That's Part 4, and yes, we'll try to come up with a headline pun for that one too.
