DMARC is published but expresses no preference (p=none)
What it is
Your domain has a valid DMARC record and it says p=none. That is the monitoring policy: it expresses no preference about mail that fails DMARC (RFC 9989, section 4.7), so every receiver keeps filtering as it sees fit.
The record is not wrong, and it is a sensible first step — it gives you the rua= reports. It is just not protection yet: nothing in it makes mail forged in your domain’s name any harder to deliver.
Testing mode: p=quarantine; t=y
A record that publishes p=quarantine together with t=y looks like enforcement, but receivers that have adopted RFC 9989 treat testing mode as p=none. Until you remove t=y, your published policy does not apply there.
How to move forward
- Read the aggregate reports that arrive at your
rua=address until every legitimate sender (your mail server, newsletter tool, invoicing system) passes SPF or DKIM alignment. - Edit the existing record — do not add a second one; two records at
_dmarccancel each other out. Changep=nonetop=quarantine, or removet=y. - Once nothing legitimate is quarantined, you can go on to
p=reject. Which one fits depends on your mail flows.
before: v=DMARC1; p=none; rua=mailto:dmarc@example.cz
after: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.czThe phased rollout is described step by step in Domain has no DMARC record. Check the result with a fresh scan at vulscan.app.
References
- Vulscan docs: DMARC from scratch
- Vulscan docs: a DMARC record that receivers discard
- RFC 9989 — DMARC — section 4.7 (p= policy values)