Walkthrough · Intermediate · 15 minutes plus a monitoring month
How to Publish a DMARC Policy
Instruct receiving servers on how to treat mail that flunks your authentication — a hands-on walkthrough in plain words that names the classic mistake before you reach it.
The short answer
One line covers it: instruct receiving servers on how to treat mail that flunks your authentication — a intermediate-level job of roughly 15 minutes plus a monitoring month.
Below is the full run of steps, the error most people trip over, and the short cut worth remembering. On Hosting & Domains plans several steps are already automated away — the guide marks each one.
By the Hosting & Domains team · Reviewed 18 August 2026
Intermediate
Experience required
5
Stages, start to finish
Free
Support included
Proven
On the platform itself
No prior knowledge assumed — a hosting account, a browser and 15 minutes plus a monitoring month of attention is the whole entry requirement. Every instruction runs on our platform exactly as printed, and carries over to any standard cPanel host.
A promise before step one: nothing here is a one-way door. Any step with teeth is flagged, and the way back is printed beside it.
The route, mapped end to end
The work falls into a few clean stages: lay the foundations first, begin in monitor mode, read the reports before you act, move up to quarantine, then reject and keep reading the feedback.
Every stage is a few minutes of unhurried clicking — the total depends mostly on how well you already know the control panel. The detailed instructions are further down; read the whole path once before you begin.
The well-worn snag
Jumping straight to p=reject without the month of monitoring. The legitimate but forgotten sender, the invoicing tool set up two years ago, starts bouncing, and the news reaches you through customer complaints.
It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.
The habit that keeps this easy for good
The large inbox providers now expect DMARC from anyone sending at volume, so what used to be best practice has become the entry fee. A p=none record alone gets you through that door while the remaining work carries on.
A minute spent now repays itself every time this job comes round again — and like almost every hosting job, come round it will.
The steps already done before you arrive
Steps that never deserved your time are taken out: certificates issue and reissue themselves, the installer handles application setup, the daily copy absorbs the what-ifs, and per-site settings live in a panel rather than a configuration file. The guide covers the remainder — the part that is actually about your site.
Should a step still misfire, support answers at any hour with an actual fix rather than a knowledge-base link and a shrug. Half the guides on this site began as repeat patterns in our ticket queue.

A quick platform makes for a short guide
Tutorials written against imaginary hosting go stale fast. Ours are written against the real thing: the same panel, installer and defaults waiting in your account.
A free SSL certificate comes with every plan and reissues itself before the old one lapses — the padlock is never yours to diarise.
- Every step checked exactly as published
- The snag named before it arrives
- The dull steps taken out of your way
- People reachable at any hour you stall
Why Hosting & Domains
Standard on every plan
Taken from real tickets
These guides came out of the support queue, so every snag flagged is one people genuinely hit.
The dull parts automated
SSL, backups and installs look after themselves here, leaving the guide to cover only what is genuinely yours.
5 steps, nothing padded
Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.
Every undo written out
Any step that could bite is marked, together with the exact way to wind it back.
Jargon never charges you
Every term is defined on the spot or linked to the jargon buster — nothing assumes prior knowledge.
Works exactly as printed
Every step is proven on the platform we run — none of the 'your host may vary' hedging.
Quick Start
Order placed to site online
- 1
Lay the foundations first
DMARC judges whether SPF and DKIM align with your domain. Both should already pass on every legitimate mail stream before enforcement makes any sense.
- 2
Begin in monitor mode
At _dmarc.yourdomain, publish a TXT record containing v=DMARC1; p=none; rua=mailto:you@yourdomain. A policy of none changes nothing about delivery; it simply starts the reports arriving.
- 3
Read the reports before you act
Aggregate reports show every source sending as your domain: the forgotten CRM, the invoicing tool, the outright impersonators. Run the raw XML through a report-parsing service and it becomes readable.
- 4
Move up to quarantine, then reject
Once every legitimate source aligns, set p=quarantine so failures go to spam. Later, move to p=reject, at which point mail forged as your domain stops being delivered at all.
- 5
Keep reading the feedback
Leave the reporting address live and look at it. New services and misconfigurations appear in the reports weeks before they appear as an incident.
Built In
Fitted to every plan
- People on the support desk every hour of every day
- A daily copy, with restores you run yourself from the panel
- Staging copies for trying a change before it goes live
- 99.9% uptime as the target, watched around the clock
- Money back within 30 days on hosting plans, 7 on reseller
- NVMe SSD storage on every tier, not only the dear ones
- SSH, Git and Composer on the developer plans
- The name's first year included when you order annually
- A renewal figure identical to the one you registered at
- No set-up charge at any point, and no joining fee
Frequently Asked
The questions that come up most
What is in a DMARC report?
Counts of messages grouped by sending source, with the SPF, DKIM and alignment verdicts against each. Never any message content. What arrives is a map of who sends as you and how their authentication performs, which is exactly what enforcement needs.
How long should p=none run before I tighten it?
A few weeks to a month. Long enough to catch senders that only fire weekly or monthly, such as invoicing runs and newsletters. Move up once the reports show clean alignment from every source you recognise.
Who stands behind Hosting & Domains?
Hosting & Domains is a trading name of UK Health Care Support Ltd, registered in England and Wales — a real company with a public filing and terms governed by English law. Running that check on any host before you hand over a domain is time well spent.
Can more than one website run on a single plan?
From the Turbo tier upward, yes — several sites, each with its own name, mailboxes and certificate, inside one account. If the extra sites belong to clients rather than to you, look at reseller hosting instead: it keeps each one properly walled off.
Keep reading
How to Set Up Domain Forwarding
Route everyone who visits one domain straight on to another — beginner level, about 5 minutes.
How to Take Payments Online
Collect money safely without dragging card data onto your own server — beginner level, about an hour.
SPF (Sender Policy Framework) (Glossary)
The plain-English definition this page rests on, with a worked example.
Web Hosting
cPanel hosting on NVMe drives — SSL, the migration and year one of the name all included.
Domain Names
Find, register and transfer names — year one free with annual hosting.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Do it properly this time.
From a first website to a rack of machines, moving up is a change to the account rather than a migration.
View Web Hosting plans