Skip to content
Search our site for answers
Login
  • Help Docs
  • API Docs
  • liquidweb.com
  • Hosting Services
    • Cloud VPS Hosting
    • Dedicated Servers
    • GPU Hosting
    • Hosting For WordPress
    • Hosting For WooCommerce
    • Email Hosting
    • VMware Hosting
    • Add-ons
  • Security & Compliance
    • SSL Certificates
    • Firewalls
    • Cloud Hosting
    • Two Factor Authentication
    • DDoS Protection
    • Compliance
    • Malware Protection
  • Domain & DNS
    • Domain Registration
    • DNS Settings
    • Nameservers
    • Subdomains
    • Domain Forwarding
    • Email DNS Setup
  • Account & Billing
    • Account Setup
    • Payment Methods
    • Billing Cycles
    • Refunds Cancellations
    • Invoices Receipts
    • Account Security
  • Email Hosting
    • Email Setup
    • Email Forwarding
    • Spam Protection
    • Microsoft 365
    • G Suite Setup
    • Account Security
    • Email Troubleshooting
  • Performance & Optimization
    • Server Optimization
    • Caching Strategies
    • Content Delivery Network
    • Database Performance
    • Image Optimization
  • Server Administration
    • Server Setup
    • SSH Access
    • Command Line Basics
    • Database Management
    • CRON Jobs
    • Apache Nginx Setup
    • Log Analysis
  • CMS & Applications
    • WordPress
    • WooCommerce
    • Magento
    • Joomla
    • Drupal
  • Backups & Recovery
    • Backup Strategies
    • Cloud Backups
    • Disaster Recovery
    • Restoring Backups
    • Raid Configurations
  • Reseller & Partner Support
    • Reseller Program
    • White Label Hosting
    • Partner Portal
    • Client Management
  • Policies & Compliance
    • Terms Of Service
    • Privacy Policy
    • GDPR Compliance
    • Acceptable Use Policy
Help Docs Email DMARC email security: improving your email security infrastructure

DMARC email security: improving your email security infrastructure

This article gives an overview of the DMARC email security and authentication protocol that you should leverage to improve your email security infrastructure.
Email Nexcess Security
7 min read

Email is one of the most vulnerable attack channels hackers use to target businesses. Therefore, preventing email-based attacks should be a top concern because it only takes one employee clicking a malicious link in an email to allow a hacker to get past all cyber defenses.

This article gives an overview of DMARC email security that you should follow to improve your email security.

Overview

Domain-based Message Authentication, Reporting, and Conformance (DMARC) is a system used to validate email. It was created to defend against the exploitation of business email domains by email spoofing, phishing attacks, and other cybercrimes. DMARC uses the Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) email authentication methods.

A crucial component of a DMARC email security solution is DMARC reporting. A domain owner can see who is sending emails on their behalf when they publish a DMARC entry in their Domain Name System (DNS) record. The domain owner can take control of the emails sent on their behalf using this information. DMARC can be used to protect your domains from phishing and email spoofing attacks.

How does DMARC work?

For email authentication, DMARC uses well-established SPF and DKIM standards. Additionally, it uses the trusted DNS.

What is a DMARC record?

A DMARC record is the backbone of a DMARC implementation, and it contains the DMARC record rulesets. If a domain is configured for DMARC, this DMARC record notifies email recipients. In that case, the domain owner’s desired policy is contained in the DMARC record.

A DMARC entry is just a DNS entry. Implementing a DMARC DNS record is the first step in using DMARC. Next, the DMARC-adopted email receivers will use this DMARC record. As a result, your DMARC policy will be taken into account when tracking all messages that have been delivered to your domain.

A DMARC record is a version of a typical DNS TXT record that is specially formatted with the name:

_dmarc.yourdomain.com

The format of a DMARC record is as follows.

_dmarc.yourdomain.com. IN TXT “v=DMARC1; p=none; rua=mailto:dmarc_rua@yourdomain.com; ruf=mailto:dmarc_ruf@yourdomain.com; pct=100”

Here is a legend for the DMARC record above:

  • v=DMARC1 defines the DMARC version.
  • p=none indicates the DMARC policy or desired to handle.
  • rua=mailto:dmarc_rua@yourdomain.com is the email address where aggregate reports should be delivered.
  • ruf=mailto:dmarc_ruf@yourdomain.com is the email address where forensic reports should be delivered.
  • pct=100 is the percentage of mail that the domain owner wants to be subject to its policy

Why is DMARC such an important factor in email security?

More than 90% of network threats use email as a gateway, and without DMARC, it could be difficult to identify whether an email is legitimate. In addition, DMARC protects domain owners’ domains from unauthorized usage by preventing phishing, spoofing, CEO fraud, and Business Email Compromise.

Phishing attacks are made visible by DMARC email security, giving you complete visibility into your email channels. DMARC is an effective technique for reducing the impact of malware and phishing threats. It can prevent spoofing, shield your firm from brand infringement, and prevent corporate email compromise and scams.

What exactly is DMARC domain alignment?

The DMARC protocol introduces the idea of “domain alignment,” which broadens the SPF and DKIM-specific domain validation. DMARC domain alignment compares the “From” domain of communication to information relevant to these other standards. For example, SPF requires that the message’s From domain and Return-Path domain match and DKIM requires a match between the message’s From domain and its DKIM d= domain.

The alignment is set as relaxed (matching base domains but allowing for various subdomains) or as strict (matching base domains but allowing for different subdomains — precisely matching the entire domain). This option is provided in the sender domain’s published DMARC policy.

What are DMARC policies?

The DMARC email security gives domain owners three options for specifying their desired treatment of mail that fails the DMARC email test.

  • p=none — this option examines the traffic in your email. There are no further actions performed.
  • p=quarantine — with this option unauthorized emails are sent to the spam folder.
  • p=reject — This option is the final policy and ultimate purpose of DMARC implementation. This rule makes sure that no illegitimate email is ever delivered.

What is a DMARC report?

As part of the DMARC Email Test, inbound mail servers generate DMARC reports. DMARC reports come in two different formats.

  • Aggregate Reports are XML files displaying statistics on the messages obtained that were stated to be from a specific domain. The reported date contains the authentication results as well as the message disposition. Aggregate reports are intended to be machine-readable.
  • Failed/Forensic Reports are individual copies of failed authentication messages wrapped in a whole email message using a specific format known as AFRF (which stands for Aggregate Failure Reporting Format). A Failed/Forensic Report can be helpful for both locating fraudulent domains and websites as well as troubleshooting any authentication issues that may be present on a domain.

SPF and DKIM: how are they related to DMARC?

Different parts of email authentication are made possible by the standards DKIM, SPF, and DMARC. They deal with related concerns. SPF enables senders to specify which IP addresses are permitted to send mail on behalf of a specific domain. DKIM offers an encryption key and digital signature that confirm an email message was not forwarded or altered.

DMARC combines the SPF and DKIM authentication mechanisms into a single framework and allows domain owners to specify how an email from their domain should be treated if an authorization test fails.

How to generate DMARC records?

You can build your domain’s DMARC record using the DMARC Record Wizard, allowing you to learn crucial details about anyone misusing your domain.

You can follow the below steps to generate a DMARC record for your domain.

  1. Enter the domain:
Enter the domain.
  1. Choose your DMARC policy:
Choose your DMARC policy.
  1.  Provide your email address to receive Aggregate Reports:
Provide your email address to receive Aggregate Reports.
  1.  Provide your email address to receive individual Failed/Forensic Reports (optional):
Provide your email address to receive individual failure reports (optional).
  1.  Choose Identifier Alignment for DKIM and SPF Alignments:
Step 5: Choose Identifier Alignment for DKIM and SPF Alignments.
  1. Choose Subdomain DMARC Policy (optional):
Choose Subdomain DMARC Policy (optional).
  1. Choose the DMARC Policy percentage: (optional).
Choose DMARC Policy percentage (optional).

 

Here is the sample DMARC record:

Here is the sample DMARC record.

 

You can also use MxToolbox DMARC Check Tool or Mimecast DMARC Analyzer online DMARC generator tools to generate DMARC records.

How to add your DMARC record to the DNS record?

You can add a DMARC record for your domain via my.nexcess.net by following the below steps:

  1. Login to my.nexcess.net.
  2. Click on DNS > DNS Zone.
  3. Click on the domain name. If there is no DNS Zone for the domain, you can go through How to create and edit DNS Zones in the Nexcess Client Portal to create a new DNS zone.
  4. Click the plus symbol (+) on the right-hand side to add new DNS records
  5. Select TXT as the Type.
  6. Enter _dmarc in the Hostname field.
  7. Enter the DMARC record in the Value field. For example, v=DMARC1; p=none; rua=mailto:test@yourdomain.com; could be what an entry looks like.
  8. Set 300 as the TTL (Time to Live).
  9. Click on the Add button to save the changes.

Conducting a DMARC email test

To conduct a DMARC Email Test, you can use the online DMARC Email Test tool. You can go through their website and follow the instructions. If your domain has a valid DMARC record, you will get the same result as in the following screenshot:

To conduct a DMARC Email Test, you can use the online DMARC Email Test tool. You can go through their website and follow the instructions. If your domain has a valid DMARC record, you will get the same  result as in this screenshot.

 

Conclusion

The DMARC protocol validates your domain’s SPF and DKIM records. The email server looks at DMARC to determine what to do with the outbound mail if it cannot locate any SPF or DKIM records. DMARC is a method that is becoming more and more crucial for preserving the integrity of email that originates from a specific domain.

Related articles

  • How to enable DKIM
  • How to enable SPF records
  • How to configure DNS records

     


Was this article helpful?
Thank you for your input.
Thank you for your feedback.
Table of Contents
  • Overview
  • How does DMARC work?
  • Conducting a DMARC email test
  • Conclusion
  • Related articles
Essential hosting resources to help your business stay ahead
Get the guides
Related hosting content
  • What is the Default Password for PostgreSQL?
  • How to set up DMARC for your domain
  • Testing and Sending Mail Using PHP

Hosting

  • Cloud Hosting
  • Dedicated Hosting
  • Email Hosting
  • GPU Hosting
  • Magento Hosting
  • Reseller Hosting
  • VPS Hosting
  • Hosting for WordPress

Additional Hosting

  • Add-ons
  • Agency Hosting
  • Application Hosting
  • Database Hosting
  • Ecommerce Hosting
  • Enterprise Hosting
  • Freelancer Hosting
  • High Availability
  • High Performance
  • HIPAA Hosting
  • PCI Compliant Hosting
  • Private Cloud Hosting
  • Server Clusters
  • Small Business Hosting
  • VPS Reseller Hosting
  • Windows Hosting
  • Windows VPS Hosting
  • Linux VPS Hosting
  • Ubuntu VPS Hosting
  • cPanel VPS Hosting
  • KVM VPS Hosting
  • WooCommerce Hosting

Servers

  • Bare Metal Servers
  • Cloud Dedicated Servers
  • Cloud VPS
  • Custom Servers
  • Dedicated Servers
  • Managed Cloud
  • Gaming Server
  • Windows Servers

Managed Hosting

  • Managed ExpressionEngine
  • Managed Craft CMS
  • Managed Cloud
  • Managed Hosting
  • Managed Hosting for WordPress
  • Managed Magento
  • Managed Servers
  • Managed VPS
  • Managed WooCommerce

Studies

  • Every Second Counts
  • Impact of Downtime
  • Hypergrowth Hosting

Resources

  • API
  • Hosting Coupons
  • Blog
  • Customer Stories
  • Ebooks
  • Help Docs
  • Migrations
  • Sitemap
  • SSL Checker
  • Webinars
  • Web Hosting Tools
  • White Papers
  • What is my IP

Hosting Basics

  • Bare Metal
  • Cloud Hosting
  • Dedicated Servers
  • Gaming VPS
  • GPUs
  • Private Cloud
  • VPS
  • Web Hosting

Partnerships

  • Hosting Affiliate Program
  • Partner Programs
  • Refer-a-Friend

Software & Design Solutions

  • GiveWP
  • IconicWP
  • Kadence WP
  • LearnDash
  • MemberDash
  • Modern Tribe
  • Restrict Content Pro
  • SolidWP
  • The Events Calendar

Get Help

  • Chat
  • Sales
  • Support

Company

  • About
  • Careers
  • Data Centers
  • Hosting Prices
  • News
  • Policies
  • Privacy Policy
  • Security
  • Terms and Conditions
  • Web Hosting Deals

Liquid Web, a web hosting company with 18 data centers globally

HostingAdvice.com logo
Liquid Web reviewLiquid Web review

© 2026 Liquid Web, LLC

Privacy Policy

* Promotions may be exclusively available to new customers and cannot be applied to existing accounts. Qualification is at the sole discretion of Liquid Web. Reach out with questions.

  • Solutions
    • Solutions by industry
      Ecommerce

      Secure, compliant infrastructure for regulated online sales

      Financial Services

      High-trust hosting built for security and compliance

      Agencies

      Fast, flexible hosting for high-traffic client projects

      Healthcare

      HIPAA-ready environments for protected health data

      Solutions by outcomes
      Compliance

      Hosting aligned with HIPAA, PCI, GDPR, and audit readiness

      Launch

      Configure a high-performance server in minutes

      Commerce Scale

      Infrastructure built to handle surges, orders, and growth

      Disaster Recovery

      Redundant, resilient systems for rapid recovery and uptime

  • VPS Hosting
    • VPS Packages
      Cloud VPS Hosting
      Windows VPS Hosting
      Linux VPS Hosting
      Add-ons & Backups
      View All VPS Hosting
  • Dedicated Servers
    • Bare Metal Packages
      Bare Metal Servers
      Cloud Metal Packages
      Managed Dedicated
      Gaming Servers
      View All Dedicated Servers

  • Managed Hosting
    • Managed Hosting
      Managed Servers
      Managed Applications
  • WordPress
    • Hosting for WordPress
      Managed Hosting for WordPress
      VPS for WordPress
      Dedicated WordPress
      WooCommerce Hosting
  • GPU Hosting
    • GPU Hosting
      NVIDIA GPU Hosting
      AI Training & Interface

  • Products
    • Compute
      Cloud Servers

      Scalable, high-speed compute

      Dedicated Servers

      Reliability, power, and control

      Private Cloud

      Isolated, enterprise-grade cloud

      GPU

      Accelerated for AI & ML

      Containers

      Portable workloads for any app

      Platform services
      Cloud Storage

      Storage for growing data needs

      Backups & DR

      Protection for critical workloads

      Global Private Fabric

      Unify networks across servers

      Security & Protection

      Advanced defense for data

      Load Balancing

      Optimized traffic distribution

      Applications
      WordPress

      Optimized for fast, secure sites

      WooCommerce

      Performance for scalable stores

      Magento

      Commerce-ready, built to scale

Log in
  • System status
  • Support | Get Help