← Back to blog

DMARC Implementation Checklist

August 30, 2026

Implementing DMARC is a controlled email-authentication project, not a single DNS change. The record can protect your domain from direct spoofing, but only after you know which services legitimately send mail and whether they pass aligned SPF or DKIM. This checklist gives a small business a safe sequence from discovery through enforcement.

1. Identify the people and systems involved

Choose an owner for the domain’s DNS and another person who understands mail operations. List every system that may send as your domain: employee mailboxes, newsletters, CRM campaigns, invoices, support replies, contact forms, booking software, and agency-run tools. For each, record the vendor, account owner, sending domain, and purpose. A forgotten sender is the most common reason an enforcement rollout creates a surprise.

2. Check the current public records

Look up SPF, DKIM, and DMARC before editing anything. Confirm that SPF has one record, that known DKIM selectors resolve, and that any DMARC record is published at _dmarc.yourdomain.com. Beacon’s free domain check provides a starting snapshot. Save the existing DNS values so you can compare results or roll back a clearly incorrect edit.

3. Configure SPF and DKIM for every sender

SPF authorizes sending systems; DKIM adds a signature. Configure both according to each provider’s current documentation, especially DKIM. Send a fresh test from every important platform and inspect the full message headers. A provider dashboard saying “verified” is useful, but receiver-side authentication results are the real test. See how to check SPF and how to check DKIM.

4. Publish a monitoring DMARC record

When the sender inventory is reasonably complete, publish a valid record with p=none and an aggregate-report address that someone actively monitors. Monitoring does not enforce a policy, but it provides evidence about sources claiming to use your domain. Keep the reporting destination secure and assign ownership; a report mailbox no one reads does not reduce risk.

5. Review alignment, not just pass results

DMARC needs aligned SPF or DKIM. A signature from an unrelated vendor domain may show DKIM pass while not supporting DMARC for your visible From address. Compare report data and fresh message headers with the sender inventory. Fix, retire, or explicitly investigate every meaningful legitimate source before moving past monitoring. Read email authentication explained if the relationship is unclear.

6. Move to quarantine gradually

Use p=quarantine with a percentage rollout when the data supports it. Start small, observe reports, and test normal messages from every major service. Quarantine gives receiving systems a reason to treat failing messages as suspicious while leaving a recovery margin. Our quarantine-policy guide explains when it is appropriate.

7. Move to reject only when stable

Reject asks receivers to refuse unauthenticated mail that claims to be your domain. It is the strongest practical anti-spoofing setting, but only after legitimate traffic is consistently aligned. Preserve the prior record and avoid combining the move with other DNS or mail-provider changes. If a verified legitimate exception appears, correct its authentication rather than abandoning the entire program.

8. Make it an operating process

Review reports after new vendor launches, email migrations, rebrands, and DNS changes. Add email-authentication review to vendor onboarding. Keep a dated change record that includes the record value, reason, owner, and test evidence. DMARC is most effective when it reflects the current sender ecosystem rather than a setup from years ago.

Run Beacon’s free check before and after each DNS stage to confirm the public SPF, DKIM, and DMARC signals.

Want a free deliverability check for your domain?
Run a free check →