Since early 2024, Gmail and Yahoo have required a specific DNS entry on every domain that sends more than roughly five thousand messages a day to their inboxes. DMARC is that entry, and for most WordPress operators it is the record that finally arrived on the setup checklist after the other two had already been in place for years.
The entry tells receiving inboxes two things. First, what to do with mail that arrives claiming to come from your domain but does not check out: deliver anyway, mark as spam, or reject outright. Second, where to send a daily report listing every service on the internet that is currently sending email claiming to be from you. The report is what makes DMARC operationally useful; the policy is what makes it operationally dangerous if you turn it on without reading the reports first. Nearly every WordPress site that has deployed DMARC in anger started by publishing the record in monitor-only mode, reading the first few weeks of reports, and only then tightening what the inboxes should do with mail that fails. This reference is that path, together with the specific places WordPress sites tend to trip on it.
What the record looks like
DMARC is published as a TXT record at a specific subdomain: _dmarc.<yourdomain>. The minimum useful record names the policy and a reporting address:
v=DMARC1; p=none; rua=mailto:[email protected]
The three tags, left to right: the version, the policy (none, quarantine, or reject), and the aggregate-report address. RFC 7489 is the specification; §6.3 lists every tag the record can carry (p, sp for subdomain policy, pct for percentage rollout, ruf for forensic reports, adkim and aspf for alignment strictness, and others).
The record lives at _dmarc.example.com, not at the domain apex. One record per domain; multiple records are a configuration error.
Policy progression: none, quarantine, reject
DMARC is deployed in three stages. The stages exist because turning the policy to reject on day one, without visibility into which legitimate services are sending as your domain, will block real mail.
p=noneis monitor mode. Receivers follow their default handling for failing messages (no DMARC-driven action), and the aggregate reports start arriving. This is where the deployment begins; it is also where Gmail and Yahoo’s bulk-sender baseline sits.p=quarantinetells receivers to deliver failing messages to the spam folder. The policy acts only on messages that fail DMARC; aligned messages are unaffected. The jump fromnonetoquarantinehappens after a few weeks of report-reading, once every legitimate sender using your domain is accounted for and producing aligned authentication.p=rejecttells receivers to drop failing messages at SMTP time. The final stage; the point at which a spoof attempt against your domain is actually blocked rather than merely visible in reports.
A pct= tag can roll a stricter policy out gradually (p=quarantine; pct=10 applies the policy to 10% of failing messages). The rollout tactic is more useful on domains sending to a wide mix of receivers than on a WordPress site, where the traffic shape is narrow and the step from none straight to quarantine after a few clean weeks is usually fine.
Alignment: the piece that trips WordPress sites up
DMARC does not simply require SPF or DKIM to pass. It requires at least one of them to pass and to align with the From: domain the recipient sees.
- SPF alignment compares the envelope-sender domain (the SMTP
MAIL FROM) to theFrom:header domain. On a WordPress site using an external relay, the envelope sender is often the relay’s bounce address (bounces.sendgrid.net,email.mailgun.org), which does not align with the site’sFrom:domain. SPF then passes but does not align, and does not count for DMARC. - DKIM alignment compares the DKIM signature’s
d=tag to theFrom:header domain. If the mailer plugin is configured to sign with the site’s own domain (not the provider’s shared signing domain), DKIM aligns. If the provider signs with its own domain by default, DKIM passes but does not align.
For most WordPress sites, DKIM alignment is the practical path to a DMARC pass: configure the provider to use a custom DKIM signature on the sending domain, add the DNS records the provider gives you, and the signature carries alignment. Gmail’s 5.7.26, 5.7.27, 5.7.30, and 5.7.40 codes (documented in reading SMTP bounce codes) are what rejection looks like when alignment fails.
Aggregate reports
The rua= address receives one XML report per day from every receiver that saw mail claiming to be from your domain. The report lists each sending IP, the message volume from it, the SPF and DKIM results, and whether DMARC passed.
The reports are what let a deployment move from p=none to p=quarantine with confidence. They list every service sending as your domain that you had forgotten about: a payroll provider, an old help-desk tool, a form-handling service, a legacy marketing platform. Each needs to produce aligned authentication, or be moved to a subdomain with its own policy, before enforcement is safe.
Reading the XML by hand is painful. Parsing DMARC aggregate reports walks through the tools that turn the raw reports into something readable, and nanoPost’s DMARC XML reader handles single reports in-browser.
What DMARC does not do
DMARC acts on authentication failure. It does nothing about reputation, content filtering, rate limiting, or the receiver’s own anti-spam policies. A message that passes DMARC can still land in spam if the sending domain’s reputation is poor or the content trips a filter. A message that fails DMARC on a p=none policy can still deliver; the policy says do nothing, and the receiver complies.
DMARC also does not protect display-name spoofing or lookalike-domain spoofing. The record protects the exact From: domain. A message From: "Your Bank" <[email protected]> passes DMARC on your-bank-security.com without issue.
For the authentication records DMARC relies on, see SPF for WordPress email. For the delivery chain the three records sit inside, how email works on WordPress is the mental model. The outbound setup walkthrough that puts SPF, DKIM, and DMARC together is set up DNS for WordPress email.
