← All topicsAuthentication & VerificationDMARC (Domain-based Message Auth)
What is DMARC? The setting that finally stops From spoofing
Question: 003.003.001 · What is DMARC? · ~3:15 · single-question video
Model note: the source names RFC 7489 and links SPF/DKIM. This video teaches DMARC itself (alignment + policy + reports) and keeps SPF/DKIM to one line each, they have their own videos.
COLD OPEN
SPF passed. DKIM passed. You still got spoofed.

You set up SPF. You set up DKIM. And somebody still sends phishing that looks like it's from you. How? Because neither of those two ever checks the name your reader actually sees. That's the exact gap DMARC was built to close.

⬡ auth-flow, SPF check lights green, DKIM check lights green, then the visible From line flashes red "still spoofable"
BEAT 1, the one-line answer

DMARC stands for Domain-based Message Authentication, Reporting, and Conformance. Say that once, then forget it. In plain words, it's a policy layer that sits on top of SPF and DKIM and does two jobs: alignment, and policy.

⬡ title-card, "DMARC = alignment + policy", small "sits on top of SPF + DKIM" underneath
BEAT 2, job one, alignment (teach ONE idea)
Does the auth domain match the From your reader sees?

Job one is alignment. SPF and DKIM each prove some domain is legit. DMARC asks the question they skip: does that proven domain match the domain in the visible From line, the one your reader actually looks at? If it lines up, DMARC passes. If it doesn't, DMARC fails, even when SPF and DKIM each passed on their own terms.

⬡ dissect, From: captain@deepcurrent.io, arrow pointing to it, "this is the domain DMARC protects"
BEAT 3, job two, policy

Job two is policy. Once DMARC catches a message that fails, you get to tell the receiving server what to do about it. Three choices: p=none means do nothing, just report it. p=quarantine means send it to spam. p=reject means don't deliver it at all. You're setting the house rules for mail that fakes your name.

⬡ split-compare, three cards, p=none (monitor) · p=quarantine (spam) · p=reject (blocked)
SUBSCRIBE

If this is the first time SPF, DKIM, and DMARC actually clicked, subscribe. We're walking through every piece of email authentication, one plain-English video at a time.

⬡ title-card, "Subscribe, the whole auth series"
BEAT 4, the bonus you didn't expect, reports

There's a third perk people forget. Every day, providers that support DMARC send you a report: who's sending mail as your domain, from which IPs, and whether it's authenticating. That's often how a company first discovers a service, or a scammer, sending under their name.

⬡ record-cards, three little report cards fanning in, "who sent as you today"
BEAT 5, where it lives

DMARC itself is one DNS record. A TXT record at _dmarc.yourdomain.com. A safe starter, monitor only, looks like this.

⬡ record-cards, TXT at _dmarc.deepcurrent.io showing v=DMARC1; p=none; rua=mailto:dmarc@deepcurrent.io
TAKEAWAY

So DMARC is the layer that ties SPF and DKIM to the name your reader sees, then tells receivers what to do when a message fakes it. One thing it does NOT do: guarantee your good mail hits the inbox. It proves who you are, placement is a separate story. Start at p=none, watch the reports, and enforce only once your real mail is clean.

⬡ title-card, "Proves who you are. Not a delivery guarantee."
NEXT / SUBSCRIBE

Next up: the three DMARC policies in detail, none, quarantine, and reject, and which one to actually start with. Subscribe and it's right there.

⬡ end-card, Subscribe + Next: "DMARC policies explained" (003.003.005)
DESCRIPTION

What is DMARC? It's the policy layer that sits on top of SPF and DKIM and does two things they can't: it checks that the authenticated domain aligns with the visible From address your reader sees, and it tells receiving servers what to do with mail that fails, p=none (monitor), p=quarantine (spam), or p=reject (block). Plus it sends you daily reports of everyone sending as your domain. DMARC lives as one TXT record at _dmarc.yourdomain.com. Important: DMARC proves who you are, it does not guarantee inbox placement, and you should start at p=none and watch reports before enforcing.

Concepts in this video: DMARC, alignment, From header, DMARC policies, aggregate reports.

Next: DMARC policies, none vs quarantine vs reject → [link 003.003.005]

New to the basics? SPF → [003.001.001] · DKIM → [003.002.001]

Parse your record free → reviewmyemails.com/tools/dmarc-parser

Full written guide → reviewmyemails.com/emailalmanac/authentication/dmarc/what-is-dmarc

#email #DMARC #deliverability

CONNECTIONS
• next: 003.003.005 DMARC policies (p=none, p=quarantine, p=reject)
• related: 003.003.016 How to start implementing DMARC · 003.003.009 What is a DMARC aggregate report
• prereq (one line each): 003.001.001 What is SPF · 003.002.001 What is DKIM
• vocab: DMARC, alignment, From header, policy, rua, aggregate report