Skip to content
emailrules.today
In forceAuthIn force 1 Mar 2015Verified 2 Aug 2026

DMARC p=none is monitoring, not enforcement

Is publishing DMARC at p=none enough to be done with DMARC?

Global

In one sentence

p=none means watch and report — it does not tell receivers to block impostors.

Emailrules interpretation

Publishing p=none often satisfies bulk-sender “have a record” checkboxes. It does not enforce your brand. Quarantine and reject do, once senders are clean. The IETF published updated DMARC specs as RFC 9989/9990/9991 in 2026; existing v=DMARC1 records still work.

Why it matters. Security decks say “we have ” while spoofers still pass. p=none is a phase, not a finish line — and generally needs real policy.

Dotted words open definitions. See how email actually works.

What to do

Your move — not a lecture

This one needs you

No platform does this for you. One concrete move, then you are done.

can sign and help you collect reports. They cannot choose your p= policy without you.

Your part: Reading (rua), fixing unaligned senders, and deciding when to tighten policy.

What to do first

Open your record and your last aggregate report. List every source that fails . Do not jump to p=reject until that list is empty or accepted.

You can skip this if: You already run p=quarantine or p=reject with clean reports and no unknown senders.

Who this applies to

Every brand that publishes for bulk compliance, board security, or brand protection — especially teams that stopped at p=none years ago.

Checklist

  • 01Keep p=none only as a deliberate monitoring phase with reporting enabled.
  • 02Inventory every system that sends as your ; fix before tightening p=.
  • 03Plan a move to quarantine then reject; treat p=none as unfinished brand protection.
  • 04When citing the protocol, prefer RFC 9989/9990/9991 (May 2026) over RFC 7489 alone.

That’s enough to act. The exact wording, the enforcement record and every primary source sit under Proof & sources, for counsel, bosses, or AI tools that need a citation. Not legal advice.

Proof

Exact position, enforcement, sources

For records and people who will check you. Skip if Monday’s move is already clear.

Source fact

A record with p=none asks receivers to send without instructing them to quarantine or reject failing mail. That satisfies many bulk-sender “publish a DMARC record” checkboxes (including Microsoft’s requirement at minimum p=none) and is a correct first step. It is not domain enforcement. Moving to p=quarantine or p=reject is how you instruct receivers to treat unauthenticated use of your — and it is a prerequisite for practical display in major clients. In May 2026 the IETF published RFC 9989 (core DMARC), RFC 9990 (aggregate reporting), and RFC 9991 (failure reporting), obsoleting RFC 7489 as the primary specification reference while remaining compatible with existing v=DMARC1 records.

What happens if you do not

Mailbox bulk rules may accept p=none. Brand spoofing continues under p=none. logo display generally will not. No universal fine for staying at p=none.

Sources

  • RFC 9989, Domain-based Message Authentication, Reporting, and Conformance (DMARC)
    Published 1 May 2026Read primary source
  • RFC 9990, DMARC Aggregate Reporting
    Published 1 May 2026Read primary source
  • Microsoft, High-volume sender requirements for Outlook.com
    Published 1 Apr 2025Read primary source

History of this page

  • Added DMARC policy ladder and RFC 9989/9990/9991 publication note.

Related

Take this with you

GET https://emailrules.today/rules/dmarc-policy-none-is-not-enforcement?format=json

Same URL, same answer, every field including the ones behind the Proof tab. An Accept: application/json header on the plain URL does the same thing. All the endpoints.