Skip to main content

Zone records · Intermediate · 15 minutes plus a monitoring month

How to publish a DMARC policy — DMARC Is an Instruction Issued by Whoever Holds the Name

Most people publish DMARC on the domain they send from and leave every other name in the portfolio wide open — which is precisely where forgery goes looking.

The short answer

DMARC is a TXT record you publish at _dmarc.yourdomain, and it is an instruction from the holder of the name: here is what to do with mail that claims to be from me and fails to line up. It governs the whole namespace under that name unless an sp= tag says otherwise. Allow 15 minutes to publish and a month of reading reports before you tighten anything.

The two halves of doing it properly are rarely done together. On the name that sends, climb slowly from p=none through quarantine to reject on the evidence in the reports. On every name that never sends — the parked ones, the old brand, the typo-catchers — there is nothing to discover, so publish a refusal on day one.

By the Hosting & Domains team · Reviewed 24 August 2026

Intermediate

Assumed knowledge

5

Stages end to end

Free

Support cost

Proven

Verification

What you need: control of the name, access to whichever panel holds its zone, and 15 minutes plus a monitoring month. Every instruction is written against cPanel as we run it, and carries over to any standard cPanel account unchanged.

Nothing on this page is a one-way door. Where a change carries a clock with it — a cache timer, a registry lock, a renewal date — the page says so before you act rather than afterwards.

A DMARC record is an instruction, not a filter

Nothing about DMARC inspects a message. It publishes a policy in your zone, and receiving servers apply that policy to mail that claims your domain and fails to line up. The authority behind it is simply that only you can write into the zone for a name you hold.

That is also why it belongs to whoever administers the domain rather than to whoever runs the mail server. The record is a statement about a name, made at the name, enforced by strangers who trust the delegation chain that led them to it.

Alignment is the part people miss

DMARC does not ask whether SPF passed. It asks whether SPF passed for a domain that matches the one in the From: header, and likewise whether the DKIM signature carries a d= matching it. Passing without alignment counts as failing, which is how a perfectly configured newsletter platform still shows up as a failure in your reports.

Relaxed alignment accepts an organisational match, so mail.yourdomain lines up with yourdomain. Strict alignment demands the exact name. Start relaxed; strict is a refinement for later, and a needless way to break a subdomain you had forgotten was sending.

The names nobody is guarding

Most portfolios contain more names than mailboxes: the previous trading name, the .co.uk bought defensively alongside the .com, the misspelling somebody registered after a bad week. None of them sends mail, none of them has a DMARC record, and forgery goes looking for exactly that combination.

A name that never sends has nothing to discover and nothing to break. Publish v=spf1 -all and p=reject on it the same afternoon you publish p=none on the name you actually use. That asymmetry is the whole trick, and it takes minutes across a portfolio.

sp=, and everything underneath the name

A policy on the organisational domain applies to its subdomains by default. That is usually what you want: it covers news.yourdomain, mail.yourdomain and the dozen hostnames a marketing tool created without asking, in a single record.

Where a subdomain has to be treated differently — a bulk-sending subdomain still warming up, say — sp= sets a separate policy for the level below without weakening the parent. Use it deliberately, and never as a way of avoiding the reports.

The climb from none to reject. p=none changes nothing about delivery and starts the aggregate reports arriving at the rua= address. Those XML files list every source sending as your domain with the SPF, DKIM and alignment verdict against each. They contain no message content and never have.

Run that for a few weeks to a month — long enough to catch senders that only fire on a monthly invoicing run — then move to p=quarantine, then p=reject. Jumping straight to reject is the standard way to discover a forgotten sender through customer complaints rather than through a report.

Mail landing at an address that carries the domain rather than a free provider

Sensible defaults, shorter instructions

Guides written against a hypothetical registrar age badly. These were written at the same zone editor, client area and deliverability screen your own account opens on.

A free SSL certificate comes with every plan and reissues itself before the old one lapses, so the padlock never becomes a date in your diary.

  • Which panel holds which power, said plainly
  • The step that silently does nothing, flagged early
  • Defaults left alone wherever the defaults are right
  • Somebody on the desk at any hour

Why Hosting & Domains

Standard on every plan

Written out of the ticket queue

These pages exist because the same questions kept arriving. Every warning on them is one somebody has genuinely needed.

The parts the account already handles

Certificates, daily copies and application installs look after themselves, so the page only covers what is genuinely yours to decide.

Stages, not padding

Each stage is a few minutes of careful clicking, and the parts that genuinely need care are marked as such.

The way back, printed beside the way in

Anything carrying a clock or a lock is marked, together with exactly how to reverse it.

Registry, registrar, host — kept apart

Each term is defined where it first appears, or linked to the jargon buster. Nothing here uses the four words as though they meant one thing.

Checked at the panel, not imagined

Every instruction was carried out on the platform we run, against a name delegated to our own nameservers. No 'your provider may differ' hedging.

Quick Start

Order placed to site online

  1. 1

    Get SPF and DKIM aligned before publishing any policy

    DMARC only ever judges alignment between what passed and what the From: header claims. Both mechanisms should already pass, and pass on your own domain, on every legitimate stream before enforcement means anything.

  2. 2

    Publish p=none with a reporting address at _dmarc

    A TXT record at _dmarc.yourdomain reading v=DMARC1; p=none; rua=mailto:you@yourdomain. Delivery is unaffected; what changes is that the aggregate reports start arriving and you finally see who sends as you.

  3. 3

    Publish a refusal on every name that never sends

    Work through the parked names, the old brand and the defensive registrations. Each gets v=spf1 -all and p=reject immediately, because there is no legitimate mail to strand and no month of evidence to gather.

  4. 4

    Read a month of reports before you tighten the sending name

    Run the raw XML through a report parser so it becomes readable. Look for the monthly senders: invoicing, statements, seasonal campaigns. They are the ones a hasty move to reject silently kills.

  5. 5

    Move to quarantine, then to reject, and keep reading

    Once every recognised source aligns, set p=quarantine so failures land in spam. Later move to p=reject. Leave the reporting address live afterwards: new integrations show up in the reports weeks before they show up as an incident.

Built In

Fitted to every plan

  • SSH, Git and Composer on the developer plans
  • The first year of the name included when you order annually
  • A renewal figure identical to the one you registered at
  • No set-up charge at any point, and no joining fee
  • A desk staffed every hour of every day
  • A daily copy of the account, restored from the panel by you
  • Staging copies, for trying a change before the live name sees it
  • 99.9% uptime as the target, watched around the clock
  • 30 days back on hosting plans, 7 on reseller
  • NVMe SSD storage on every tier, not only the expensive ones

Frequently Asked

Questions we field again and again

Do parked and redirect-only domains need DMARC?

They need it more than the domain you actually use, because nobody is watching them. A name with no mail service has no legitimate sending to protect, so v=spf1 -all together with p=reject can go up on the day you buy it. Every defensive registration in the portfolio deserves the same two records.

Does a policy on the main domain cover its subdomains?

By default, yes — the organisational domain's policy applies downwards, which is what makes a single record worth publishing. The sp= tag overrides that for the level below, which is worth using when a bulk-sending subdomain is still warming up and you do not want its failures judged at the parent's standard.

Which company holds the registrations?

Hosting & Domains is a trading name of Azaanex Inc., federally incorporated in Canada, with terms governed by Ontario law. Checking that a registrar is a real company with a public filing before handing it a domain is five minutes very well spent, and applies to us as much as to anybody.

Can several of my names live on one plan?

From the Turbo tier upward, yes — several sites, each with its own name, mailboxes and certificate, inside one account. Where the extra names belong to clients rather than to you, reseller hosting is the better fit, because it keeps each one properly walled off.

Keep reading

  • How to Set Up Domain Forwarding

    Send everyone who arrives at one name straight on to another — beginner, about 5 minutes.

  • Web Hosting

    cPanel hosting on NVMe drives, with SSL, the migration and year one of the name included.

  • Domain Names

    Search, register and transfer names — the first year included with an annual plan.

Changing provider? Work through this checklist beforehand.

A straightforward running order for a migration your visitors never spot: which files travel first, how to bring the mail across without dropping a single message, the right moment to repoint DNS, and the two errors that sit behind almost every outage we get called in to fix.

You get the checklist, followed now and then by a note on keeping a site responsive. Unsubscribe whenever you want; the privacy policy covers the rest.

Get the name under proper control.

From a single name to a portfolio, growing is a change to the account rather than another migration.

View Web Hosting plans