DMARC is published but expresses no preference (p=none)

What it is

Your domain has a valid DMARC record and it says p=none. That is the monitoring policy: it expresses no preference about mail that fails DMARC (RFC 9989, section 4.7), so every receiver keeps filtering as it sees fit.

The record is not wrong, and it is a sensible first step — it gives you the rua= reports. It is just not protection yet: nothing in it makes mail forged in your domain’s name any harder to deliver.

Testing mode: p=quarantine; t=y

A record that publishes p=quarantine together with t=y looks like enforcement, but receivers that have adopted RFC 9989 treat testing mode as p=none. Until you remove t=y, your published policy does not apply there.

How to move forward

  1. Read the aggregate reports that arrive at your rua= address until every legitimate sender (your mail server, newsletter tool, invoicing system) passes SPF or DKIM alignment.
  2. Edit the existing record — do not add a second one; two records at _dmarc cancel each other out. Change p=none to p=quarantine, or remove t=y.
  3. Once nothing legitimate is quarantined, you can go on to p=reject. Which one fits depends on your mail flows.
before: v=DMARC1; p=none; rua=mailto:dmarc@example.cz
after:  v=DMARC1; p=quarantine; rua=mailto:dmarc@example.cz

The phased rollout is described step by step in Domain has no DMARC record. Check the result with a fresh scan at vulscan.app.

References