DMARC is the policy layer that tells receiving mail systems what to do when a message claiming your domain fails authentication, and how to report what they saw.
DMARC is the policy layer that tells receiving mail systems what to do when a message claiming your domain fails authentication, and how to report what they saw.
Why DMARC exists
Anyone can put your domain in the From header of an email. Without authentication, receivers have little reason to trust that the message really came from you. Phishing and invoice fraud rely on that gap.
SPF and DKIM each prove parts of the journey. DMARC ties them to the visible From domain (alignment) and publishes a domain-owner policy: monitor, quarantine, or reject failing mail. It also asks receivers to send aggregate reports so you can see who is sending as you.
For European organisations, DMARC is not a marketing badge. It is operational hygiene: fewer successful lookalike campaigns, clearer visibility of shadow IT senders, and a path to stricter inbox treatment of forged mail.
How DMARC relates to SPF and DKIM
SPF authorises sending IP addresses for a domain via a DNS TXT record. DKIM attaches a cryptographic signature that receivers verify with a public key in DNS. Either can pass while the other fails.
DMARC requires alignment: the domain that passed SPF or DKIM must match (or be a parent of) the From domain, depending on relaxed or strict mode. A newsletter that signs with its own domain but puts your brand in From will fail DMARC until you authorise and align it.
Practical rule: fix SPF and DKIM for every legitimate sender first, then publish DMARC at p=none so reports teach you what is still broken, then tighten policy.
What a DMARC record contains
DMARC is a TXT record at _dmarc.yourdomain. The important tags are:
v=DMARC1: version marker.
p=: policy for the organisational domain (none, quarantine, or reject).
sp=: optional policy for subdomains.
rua=: URI for aggregate XML reports (usually a mailto: address).
ruf=: optional URI for forensic samples (often unused; privacy and volume caveats).
adkim= and aspf=: alignment mode (r relaxed, s strict).
pct=: percentage of failing mail to which the policy applies while you ramp up.
MailControl on NovaMX gives you the exact record to publish and can host the rua address so reports become readable charts instead of raw XML.
Policy stages and when to move
p=none (monitor)
Receivers do not change delivery based on DMARC failure. You still receive reports. Stay here until almost all legitimate senders pass alignment for two to four weeks.
p=quarantine
Failing mail is treated as suspicious (often spam folder). Use this as a short bridge so you notice remaining gaps without hard bounces.
p=reject
Failing mail is refused. This is the goal for brand protection, but only after sources are clean. Jumping here early blocks CRM, ticketing and newsletter tools you still need.
Benefits
Reduces successful phishing that abuses your exact From domain.
Surfaces unknown senders (shadow IT, compromised tools, lookalikes using your domain incorrectly).
Improves trust signals for BIMI in supporting inboxes (strict DMARC is a common prerequisite).
Gives operators a shared language with IT and marketing: which tools are authorised.
Supports Internet.nl and Hardenize style mail checks that expect authentication and reporting.
Pitfalls and failure modes
Tightening policy before all senders pass alignment.
Forgetting a low-volume tool (billing, HR, parking tickets) that only appears after quarantine.
Pointing rua at an unread mailbox so problems stay invisible.
Publishing DMARC before SPF/DKIM exist, which creates noisy reports without protection.
Misunderstanding alignment: SPF can pass on a bounce domain while From still fails DMARC.
Assuming DMARC stops every lookalike domain (it does not; lookalike watching is a separate control).
Treating p=reject as a one-time project instead of ongoing sender inventory.
How NovaMX MailControl helps
NovaMX MailControl turns DMARC from XML files into an operational workflow in My NovaMX. After domain verification you can start with MailControl Free for basic monitoring, order DMARC Reports for hosted rua and source intelligence, use Managed DMARC for a guided policy ramp, or pick a MailControl bundle that also includes SPF flattening and transport reporting.
You do not need NovaMX hosting. Publish the DNS records where your zone already lives, or let NovaMX DNS publish them when we host the zone. The free mail check on novamx.eu shows whether SPF, DKIM and DMARC are present before you buy anything.
Related reading
Use the step-by-step DMARC setup guide when you are ready to publish records. Read the DMARC Reports and Managed DMARC background pages to choose the right MailControl add-on. Pair with SPF and DKIM guides so alignment makes sense.
Common questions
Does DMARC encrypt email?
No. DMARC is about authenticity and policy, not content encryption. Use TLS in transport (and MTA-STS where relevant) separately.
Is DMARC required by law in the Netherlands?
There is no general consumer law that every .nl site must publish DMARC. It is still strongly recommended for any domain that sends mail, and many security baselines and customer questionnaires expect it.
Can I run DMARC without changing my website host?
Yes. After you verify the domain in My NovaMX, MailControl works while the website stays elsewhere. You only publish DNS records.
What is the difference between rua and ruf?
rua is aggregate daily XML summaries. ruf is optional forensic samples of failing messages. Most organisations start with rua only.
DMARC is de beleidslaag die ontvangende mailsystemen vertelt wat te doen als een bericht namens uw domein de authenticatie faalt, en hoe daarover te rapporteren.
Waarom DMARC bestaat
Iedereen kan uw domein in de From-header van een e-mail zetten. Zonder authenticatie hebben ontvangers weinig reden om te geloven dat het bericht echt van u komt. Phishing en factuurfraude maken daar gebruik van.
SPF en DKIM bewijzen elk een deel van de reis. DMARC koppelt ze aan het zichtbare From-domein (alignment) en publiceert een beleid van de domeineigenaar: monitoren, in quarantaine plaatsen, of falende mail weigeren. Ontvangers sturen ook aggregaatrapporten zodat u ziet wie namens u verzendt.
Voor Europese organisaties is DMARC geen marketingbadge. Het is operationele hygiëne: minder succesvolle lookalike-campagnes, zicht op schaduw-IT-verzenders, en een pad naar strengere behandeling van vervalste mail.
Hoe DMARC samenhangt met SPF en DKIM
SPF autoriseert verzendende IP-adressen via een DNS-TXT-record. DKIM voegt een cryptografische handtekening toe die ontvangers verifiëren met een publieke sleutel in DNS. Een van beide kan slagen terwijl de andere faalt.
DMARC vereist alignment: het domein dat SPF of DKIM haalde moet overeenkomen met (of een ouder zijn van) het From-domein, afhankelijk van relaxed of strict mode. Een nieuwsbrief die met een eigen domein tekent maar uw merk in From zet, faalt DMARC tot u die bron autoriseert en uitlijnt.
Praktische regel: herstel eerst SPF en DKIM voor elke legitieme verzender, publiceer daarna DMARC op p=none zodat rapporten tonen wat nog kapot is, en verscherp dan het beleid.
Wat er in een DMARC-record staat
DMARC is een TXT-record op _dmarc.uwdomein. Belangrijke tags:
v=DMARC1: versiemarker.
p=: beleid voor het organisatiedomein (none, quarantine of reject).
sp=: optioneel beleid voor subdomeinen.
rua=: URI voor aggregaat-XML-rapporten (meestal mailto:).
ruf=: optionele URI voor forensische samples (vaak ongebruikt; privacy- en volumebezwaren).
adkim= en aspf=: alignmentmodus (r relaxed, s strict).
pct=: percentage falende mail waarop het beleid geldt tijdens opschalen.
MailControl op NovaMX geeft het exacte record om te publiceren en kan het rua-adres hosten zodat rapporten leesbare grafieken worden.
Beleidstappen en wanneer u doorschakelt
p=none (monitor)
Ontvangers wijzigen aflevering niet op basis van DMARC-falen. U ontvangt wel rapporten. Blijf hier tot bijna alle legitieme verzenders twee tot vier weken alignment halen.
p=quarantine
Falende mail wordt verdacht behandeld (vaak spammap). Gebruik dit als korte brug zodat u restgaten ziet zonder harde bounces.
p=reject
Falende mail wordt geweigerd. Dit is het doel voor merkbescherming, maar alleen na schone bronnen. Te vroeg springen blokkeert CRM, ticketing en nieuwsbrieven die u nog nodig heeft.
Voordelen
Vermindert succesvolle phishing die uw exacte From-domein misbruikt.
Brengt onbekende verzenders in beeld (schaduw-IT, gecompromitteerde tools, verkeerd gebruik van uw domein).
Versterkt vertrouwenssignalen voor BIMI in ondersteunende inboxen (streng DMARC is vaak vereist).
Geeft IT en marketing een gedeelde taal: welke tools zijn geautoriseerd.
Ondersteunt Internet.nl- en Hardenize-achtige mailchecks die authenticatie en rapportage verwachten.
Valkuilen en faalmodi
Beleid verscherpen voordat alle verzenders alignment halen.
Een low-volume tool vergeten die pas na quarantine opduikt.
rua naar een ongelezen mailbox laten wijzen.
DMARC publiceren vóór SPF/DKIM bestaan.
Alignment verkeerd begrijpen: SPF kan slagen op een bounce-domein terwijl From nog faalt.
Aannemen dat DMARC elk lookalike-domein stopt (dat doet het niet).
p=reject als eenmalig project zien in plaats van doorlopende verzenderinventaris.
Hoe NovaMX MailControl helpt
NovaMX MailControl maakt van DMARC een operationele workflow in My NovaMX in plaats van XML-bestanden. Na domeinverificatie start u met MailControl Free voor basismonitoring, bestelt u DMARC Reports voor gehoste rua en broninzicht, gebruikt u Managed DMARC voor een begeleide beleidstrap, of kiest u een MailControl-bundel die ook SPF flattening en transportrapportage bevat.
U heeft geen NovaMX-hosting nodig. Publiceer DNS waar uw zone al staat, of laat NovaMX DNS publiceren als wij de zone hosten. De gratis mailcheck op novamx.eu toont of SPF, DKIM en DMARC aanwezig zijn voordat u iets koopt.
Gerelateerde lectuur
Gebruik de DMARC-stappengids wanneer u records wilt publiceren. Lees de achtergrondpagina’s over DMARC Reports en Managed DMARC om de juiste MailControl-add-on te kiezen. Combineer met de SPF- en DKIM-gidsen zodat alignment klopt.
Veelgestelde vragen
Versleutelt DMARC e-mail?
Nee. DMARC gaat over authenticiteit en beleid, niet over inhoudsversleuteling. Gebruik TLS in transport (en MTA-STS waar relevant) apart.
Is DMARC wettelijk verplicht in Nederland?
Er is geen algemene consumentenwet die elk .nl-domein DMARC verplicht. Het blijft sterk aangeraden voor elk domein dat mail verstuurt, en veel securitybaselines verwachten het.
Kan ik DMARC draaien zonder van websitehost te wisselen?
Ja. Na domeinverificatie in My NovaMX werkt MailControl terwijl de website elders blijft. U publiceert alleen DNS-records.
Wat is het verschil tussen rua en ruf?
rua zijn aggregaat dagelijkse XML-samenvattingen. ruf zijn optionele forensische samples van falende berichten. De meeste organisaties beginnen alleen met rua.