Skip to main content

What is DMARC?

DMARC is a rule in the DNS of your domain. It tells inbox providers, such as Gmail and Yahoo, what to do with email that fails authentication. Authentication is the SPF and DKIM check. DMARC protects your domain against spoofing, where a bad actor sends email that pretends to come from you. Google and Yahoo require a DMARC record for bulk senders. TextYess adds one for you when you set up a sending domain.

The three DMARC policies

A DMARC record has a policy value, written as p=. There are three policies:
  • p=none — Monitor only. The inbox provider takes no action on email that fails authentication. It still delivers the email. This policy meets the Google and Yahoo rule, but it does not stop spoofing.
  • p=quarantine — The inbox provider sends failed email to the spam folder.
  • p=reject — The inbox provider blocks failed email. The recipient never sees it.
none gives the least protection. reject gives the most.

What TextYess sets up

TextYess creates your DMARC record with p=none. This is the safe default. It meets the bulk-sender rule, and it never blocks your legitimate email. TextYess is designed to send your email from a dedicated subdomain, for example updates.yourbrand.com. We recommend that only TextYess sends from this subdomain.

When to move to enforcement

Move to p=quarantine or p=reject when you want to stop spoofing of your domain.
Enforcement filters or blocks every email from the domain that fails SPF or DKIM. Move to enforcement only after you make sure that all legitimate email from the domain passes authentication.
If only TextYess sends from the subdomain, enforcement is safe. TextYess email passes authentication, so enforcement does not filter it. You can then move the subdomain to enforcement with low risk. Do not change the DMARC policy on your root domain (for example yourbrand.com) until you check every service that sends email from it. A missed service loses its email at enforcement.

How to move to enforcement

1

Open your DNS provider

Sign in to the DNS provider for your domain.
2

Find the DMARC record

Find the TXT record named _dmarc.<your-sending-subdomain>. Its value starts with v=DMARC1; p=none.
3

Change the policy

Change p=none to p=quarantine. Save the record.
4

Watch delivery, then move to reject

Watch your email delivery for two to four weeks. If your legitimate email arrives as normal, change p=quarantine to p=reject for full protection.

BIMI: your brand logo in the inbox

BIMI (Brand Indicators for Message Identification) shows your brand logo next to your sender name in Gmail and Apple Mail. BIMI needs three things:
  1. A DMARC policy of p=quarantine or p=reject. BIMI does not work with p=none. Move to enforcement first.
  2. Your logo as an SVG file, in the SVG Tiny PS profile, on a square canvas.
  3. A Verified Mark Certificate (VMC) for Gmail. A VMC proves that you own the trademark for the logo. You buy it from a certificate provider, and it has a yearly cost.
You then add a TXT record named default._bimi.<your-domain>. Its value points to the logo and the certificate:
TextYess does not manage BIMI for you today. This page explains what BIMI needs, so you can decide if it is worth the cost. Contact support if you want help.