DMARC p=none is monitoring, not enforcement
Is publishing DMARC at p=none enough to be done with DMARC?
In one sentence
p=none means watch and report — it does not tell receivers to block impostors.
Plain English
Publishing p=none often satisfies bulk-sender “have a record” checkboxes. It does not enforce your brand. Quarantine and reject do, once senders are clean. The IETF published updated DMARC specs as RFC 9989/9990/9991 in 2026; existing v=DMARC1 records still work.
Why it matters. Security decks say “we have ” while spoofers still pass. p=none is a phase, not a finish line — and generally needs real policy.
Dotted words open definitions. Full glossary.
What to do
Your move — not a lecture
This one needs you
No platform does this for you. One concrete move, then you are done.
can sign and help you collect reports. They cannot choose your p= policy without you.
Your part: Reading (rua), fixing unaligned senders, and deciding when to tighten policy.
What to do first
Open your record and your last aggregate report. List every source that fails . Do not jump to p=reject until that list is empty or accepted.
You can skip this if: You already run p=quarantine or p=reject with clean reports and no unknown senders.
Who this applies to
Every brand that publishes for bulk compliance, board security, or brand protection — especially teams that stopped at p=none years ago.
Checklist
- 01Keep p=none only as a deliberate monitoring phase with reporting enabled.
- 02Inventory every system that sends as your ; fix before tightening p=.
- 03Plan a move to quarantine then reject; treat p=none as unfinished brand protection.
- 04When citing the protocol, prefer RFC 9989/9990/9991 (May 2026) over RFC 7489 alone.
That’s enough to act. Sources and exact wording are below for counsel, bosses, or AI tools that need a citation. Not legal advice.
Proof
Exact position, enforcement, sources
For records and people who will check you. Skip if Monday’s move is already clear.
The exact position
A record with p=none asks receivers to send without instructing them to quarantine or reject failing mail. That satisfies many bulk-sender “publish a DMARC record” checkboxes (including Microsoft’s requirement at minimum p=none) and is a correct first step. It is not domain enforcement. Moving to p=quarantine or p=reject is how you instruct receivers to treat unauthenticated use of your — and it is a prerequisite for practical display in major clients. In May 2026 the IETF published RFC 9989 (core DMARC), RFC 9990 (aggregate reporting), and RFC 9991 (failure reporting), obsoleting RFC 7489 as the primary specification reference while remaining compatible with existing v=DMARC1 records.
What happens if you do not
Mailbox bulk rules may accept p=none. Brand spoofing continues under p=none. logo display generally will not. No universal fine for staying at p=none.
Sources
- RFC 9989, Domain-based Message Authentication, Reporting, and Conformance (DMARC)Published 1 May 2026Read primary source
- RFC 9990, DMARC Aggregate ReportingPublished 1 May 2026Read primary source
- Microsoft, High-volume sender requirements for Outlook.comPublished 1 Apr 2025Read primary source
Related
History of this page
- Added DMARC policy ladder and RFC 9989/9990/9991 publication note.