Reach DMARC p=reject without breaking email
Published 28 April 2026 · Editorial update 6 September 2026 · 2 min read · Enternovate

DMARC helps receiving systems decide what to do with mail that fails authentication alignment for your domain. It reduces one route to domain impersonation. It does not stop lookalike domains, compromised accounts or every form of invoice fraud.
Inventory legitimate senders first: your mail platform, invoicing system, CRM and marketing tools. DNS inspection is useful, but it cannot establish the full sender inventory or verify an unknown DKIM selector by itself.
Begin with a monitoring policy and aggregate reporting. Observe a representative business cycle, including infrequent payroll or campaign mail. Reports can be incomplete, and some receivers do not send them. Review access and retention because reports contain operational information.
DMARC passes when at least one of SPF or DKIM both passes and aligns with the visible From domain. Confirm each sender's setup with its administrator. Test forwarding and mailing-list paths, which can behave differently from direct delivery.
Move towards quarantine and reject only after legitimate sources are accounted for. Keep a rollback record, monitor delivery and use staged controls supported by your receiving environment. Enternovate can help scope an email-security review; DNS changes still need an authorised owner and validation.