{"id":2386,"date":"2018-12-17T09:17:56","date_gmt":"2018-12-17T17:17:56","guid":{"rendered":"https:\/\/www.cloudinsidr.com\/content\/?p=2386"},"modified":"2021-12-28T17:22:03","modified_gmt":"2021-12-29T01:22:03","slug":"how-to-set-up-dmarc","status":"publish","type":"post","link":"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/","title":{"rendered":"How to set up DMARC"},"content":{"rendered":"<p>The relentless onslaught of spam continues to drive mail administrators up the proverbial wall. DMARC, the unofficial successor to SPF (Sender Policy Framework), holds the promise of more email legitimacy, but can it deliver? Here is how you can put DMARC to the test.<\/p>\n<p><!--more--><\/p>\n<h2>Step 1. Verify your DNS configuration<\/h2>\n<p>Make sure you have your A\/AAA and MX records set up correctly. For IPv4 traffic, your DNS zone needs at least one record of type A pointing to an IPv4 address; for IPv6 traffic, you need at least one record of the type AAA pointing to a valid IPv6 record (currently, the latter one is optional, but this will change).<\/p>\n<h2>Step 2. Set up SPF<\/h2>\n<p class=\"r\">DMARC relies on Sender Policy Framework (SPF). You will need a valid SPF record to set up DMARC. Make sure it&#8217;s one of the type TXT; the type SPF is deprecated. A valid SPF record could look something like this:<\/p>\n<pre>\"v=spf1 ip4:12.23.34.567 ip4:34.43.24.65 a:smtp.yourdomain.tld a mx ?all\"<\/pre>\n<p class=\"r\">Increment your SOA serial number, save your changes and wait for your NS servers to catch up. (Your configuration changes may not reflect in testing tools immediately.)<\/p>\n<p>To validate or pre-validate your SPF syntax, head over to of these services:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"https:\/\/www.dmarcanalyzer.com\/spf\/checker\/\" target=\"_blank\" rel=\"noopener\">https:\/\/www.dmarcanalyzer.com\/spf\/checker\/<\/a><\/p>\n<p style=\"padding-left: 30px;\"><a href=\"https:\/\/vamsoft.com\/support\/tools\/spf-syntax-validator\" target=\"_blank\" rel=\"noopener\">https:\/\/vamsoft.com\/support\/tools\/spf-syntax-validator<\/a><\/p>\n<h2>Step 3. Generate and test your DMARC record<\/h2>\n<p>We recommend the DMARC RECORD GENERATOR by <a href=\"https:\/\/mxtoolbox.com\/\" target=\"_blank\" rel=\"noopener\">MX TOOLBOX<\/a>\u00a0available at:<\/p>\n<p style=\"padding-left: 30px;\"><a href=\"https:\/\/mxtoolbox.com\/DMARCRecordGenerator.aspx\" target=\"_blank\" rel=\"noopener\">https:\/\/mxtoolbox.com\/DMARCRecordGenerator.aspx<\/a><\/p>\n<p>Make sure you check out all options available in the wizard. Copy the generated record into a text editor and adjust the mailto: options to reflect your desired setup.<\/p>\n<p>Next, test your DMARC record thoroughly. We recommend the\u00a0DMARC Inspector by <a href=\"https:\/\/dmarcian.com\/dmarc-inspector\/\" target=\"_blank\" rel=\"noopener\">DMARcian<\/a>:<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"Tf8OEgmgrK\"><p><a href=\"https:\/\/dmarcian.com\/dmarc-inspector\/\">DMARC Inspector<\/a><\/p><\/blockquote>\n<p><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;DMARC Inspector&#8221; &#8212; dmarcian\" src=\"https:\/\/dmarcian.com\/dmarc-inspector\/embed\/#?secret=8o5r4JfqV5#?secret=Tf8OEgmgrK\" data-secret=\"Tf8OEgmgrK\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>This utility lists all DMARC tags it discovers as well as implicit tags (those that take effect even though you have not declared them) and explains each one in plain English. Another service worth trying is <a href=\"https:\/\/secure.fraudmarc.com\/tool\/dmarc\/\" target=\"_blank\" rel=\"noopener\">Fraudmarc<\/a>.<\/p>\n<h2>Step 4. Complete your DNS configuration<\/h2>\n<p>You can send DMARC reports either to an email address on the same domain (Option A) or on another domain (Option B).<\/p>\n<figure id=\"attachment_2412\" aria-describedby=\"caption-attachment-2412\" style=\"width: 1024px\" class=\"wp-caption alignnone\"><a href=\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/dmarc-example\/\" rel=\"attachment wp-att-2412\"><img loading=\"lazy\" decoding=\"async\" class=\"size-large wp-image-2412\" src=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/12\/dmarc-example-1024x346.png\" alt=\"DMARC configuration example on Route 53\" width=\"1024\" height=\"346\" srcset=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/12\/dmarc-example-1024x346.png 1024w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/12\/dmarc-example-300x101.png 300w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/12\/dmarc-example-768x260.png 768w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/12\/dmarc-example-295x100.png 295w, https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/12\/dmarc-example-600x203.png 600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/a><figcaption id=\"caption-attachment-2412\" class=\"wp-caption-text\">DMARC configuration example on Route 53<\/figcaption><\/figure>\n<h3>Option A. Send DMARC reports to an email address on the same domain<\/h3>\n<p>If you intend to send DMARC reports to an email address on the same domain they are generated for, use the following settings:<\/p>\n<pre class=\"gwt-Label GEHJJTKDB2D GEHJJTKDPIE\" style=\"padding-left: 30px;\">label: _dmarc.yourdomain.tld.\r\ntype: TXT\r\nalias: no\r\nTTL (in seconds, example value): 300\r\nValue (example value, enter without quotes):\u00a0\"v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.tld; ruf=mailto:dmarc@yourdomain.tld; fo=1; adkim=r; aspf=r\"<\/pre>\n<p style=\"padding-left: 30px;\">With this setup,\u00a0emails will be delivered even if they fail DMARC validation.<\/p>\n<p style=\"padding-left: 30px;\">Select the routing policy and save the record set. Be sure to increment your SOA serial.<\/p>\n<p>You are now ready to validate your DMARC record (see step 5 below).<\/p>\n<div>\n<h3>Option B. Send DMARC reports to an email address on another domain<\/h3>\n<\/div>\n<p>To send your DMARC reports outside of the domain that generates them, you need to authorize the other domain to receive them. Here is how to do that.<\/p>\n<h4 style=\"padding-left: 30px;\">[Option B, step 1.] Create a new record set in the zone that will send DMARC reports<\/h4>\n<pre class=\"gwt-Label GEHJJTKDB2D GEHJJTKDPIE\" style=\"padding-left: 30px;\">label: _dmarc.domain-that-sends-DMARC-reports.tld.\r\ntype: TXT\r\nalias: no\r\nTTL (in seconds, example value): 300\r\nValue (example value, enter without quotes):\u00a0\"v=DMARC1; p=none; rua=mailto:dmarc@domain-that-receives-reports.tld; ruf=mailto:dmarc@yourdomain-that-receives-reports.tld; fo=1; adkim=r; aspf=r\"<\/pre>\n<div style=\"padding-left: 30px;\">Select the routing policy and save.<\/div>\n<h4 style=\"padding-left: 30px;\">[Option B, step 2.] Create a new record set in the zone that will receive DMARC reports<\/h4>\n<p style=\"padding-left: 30px;\">Open the DNS configuration of the zone that will receive your DMARC reports for\u00a0yourdomain.tld. Create a new record set using these settings:<\/p>\n<pre style=\"padding-left: 30px;\">label (omit the angle brackets): &lt;domain-that-sends-DMARC-reports.tld&gt;._report._dmarc.&lt;domain-that-receives-reports.tld&gt;.\r\ntype: TXT\u00a0\r\nalias: no\r\nTTL (in seconds, example value): 300\r\nValue (example value, enter without quotes): \"v=DMARC1\"\r\n<\/pre>\n<p style=\"padding-left: 30px;\">Select the routing policy and save.\u00a0Be sure to increment your SOA serial.<\/p>\n<p>You are now ready to validate your DMARC record (see step 5 below).<\/p>\n<h2>Step 5. Keep a watchful eye on your DMARC reports<\/h2>\n<p>Verify changes to your DNS configuration using one of the services listed in Step 3 above.<\/p>\n<p>Going forward, you will need to keep an eye on your DMARC reports, particularly if you intend to use a restrictive configuration. It almost goes without saying that if you encounter any undesirable activity, you should take action on the reports immediately.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The relentless onslaught of spam continues to drive mail administrators up the proverbial wall. DMARC, the unofficial successor to SPF (Sender Policy Framework), holds the promise of more email legitimacy, but can it deliver? Here is how you can put DMARC to the test.<\/p>\n","protected":false},"author":1,"featured_media":2390,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[233,2],"tags":[250,60,147,251],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v14.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>How to set up DMARC - CloudInsidr<\/title>\n<meta name=\"robots\" content=\"index, follow\" \/>\n<meta name=\"googlebot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta name=\"bingbot\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to set up DMARC - CloudInsidr\" \/>\n<meta property=\"og:description\" content=\"The relentless onslaught of spam continues to drive mail administrators up the proverbial wall. DMARC, the unofficial successor to SPF (Sender Policy Framework), holds the promise of more email legitimacy, but can it deliver? Here is how you can put DMARC to the test.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/\" \/>\n<meta property=\"og:site_name\" content=\"CloudInsidr\" \/>\n<meta property=\"article:published_time\" content=\"2018-12-17T17:17:56+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-12-29T01:22:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/09\/DMARC-OK.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1621\" \/>\n\t<meta property=\"og:image:height\" content=\"731\" \/>\n<meta name=\"twitter:card\" content=\"summary\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#website\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/\",\"name\":\"CloudInsidr\",\"description\":\"Cyber security, infotech\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.cloudinsidr.com\/content\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/wp-content\/uploads\/2018\/09\/DMARC-OK.png\",\"width\":1621,\"height\":731,\"caption\":\"DMARC\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/#webpage\",\"url\":\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/\",\"name\":\"How to set up DMARC - CloudInsidr\",\"isPartOf\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/#primaryimage\"},\"datePublished\":\"2018-12-17T17:17:56+00:00\",\"dateModified\":\"2021-12-29T01:22:03+00:00\",\"author\":{\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#\/schema\/person\/dd6ee9cb21cf05763fd7cff3d6f11b2b\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cloudinsidr.com\/content\/how-to-set-up-dmarc\/\"]}]},{\"@type\":[\"Person\"],\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#\/schema\/person\/dd6ee9cb21cf05763fd7cff3d6f11b2b\",\"name\":\"Cloud Insidr\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.cloudinsidr.com\/content\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8b2fa1415b3d573b97d818b8f8f83b7c?s=96&d=mm&r=g\",\"caption\":\"Cloud Insidr\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/2386"}],"collection":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/comments?post=2386"}],"version-history":[{"count":28,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/2386\/revisions"}],"predecessor-version":[{"id":2780,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/posts\/2386\/revisions\/2780"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/media\/2390"}],"wp:attachment":[{"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/media?parent=2386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/categories?post=2386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudinsidr.com\/content\/wp-json\/wp\/v2\/tags?post=2386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}