Skip to main content
Emailens
Blog
PK
·Founder, Emailens
Jul 18, 2026·6 min read

DMARC Policy Modes: p=none vs Quarantine vs Reject

The p= tag is the core decision in your DMARC record. Here's what each policy mode does, how to transition safely, and how to reach full enforcement without dropping legitimate customer mail.

Quick Answer: Selecting the Right DMARC Policy Mode

DMARC offers three progressive policy modes: p=none (monitor-only mode to audit sending sources via XML reports), p=quarantine (diverts unauthenticated mail to spam folders), and p=reject (instructs inboxes to block unauthorized mail completely). Always monitor under p=none first to ensure all legitimate services pass SPF/DKIM alignment before enforcing quarantine or reject.

The three modes

A message "fails DMARC" when neither SPF nor DKIM both authenticates and aligns with the visible From: domain. The policy decides what happens next:

p=noneMonitor

What it does: Nothing changes about delivery. Receivers evaluate SPF, DKIM and alignment, and, crucially, send you aggregate reports. Failing mail is still delivered normally.

When to use it: Where everyone starts. Turn it on, collect reports, and build a complete picture of every source sending as your domain before you enforce anything.

p=quarantineFilter

What it does: Mail that fails DMARC is treated as suspicious, typically routed to the spam or Junk folder rather than the inbox. It still gets delivered, just not prominently.

When to use it: The middle step. Once your legitimate sources pass reliably, quarantine limits the damage of spoofed mail without the hard cutoff of reject. Watch reports for collateral damage.

p=rejectBlock

What it does: Mail that fails DMARC is rejected at the SMTP layer: it never reaches the recipient at all. This is full enforcement and the strongest anti-spoofing protection.

When to use it: The destination. Publish it only when your reports show legitimate mail passing consistently. It's also a prerequisite for BIMI brand logos in the inbox.

The receiver has the final say

Your policy is a request, not a command. Receiving servers can, and do, override it. A mailbox provider might deliver a p=reject message from a high-reputation source anyway, or quarantine something that technically passed. That's why aggregate reports record two things: the disposition (what the receiver actually did) and the policy you published. When they disagree, the report is telling you how much the receiver trusts, or distrusts, your mail.

How to move up safely

The whole point of starting at p=none is to earn your way to p=reject without breaking delivery. A safe progression:

  1. Publish p=none with an rua= address. Do nothing else for a couple of weeks. Let the reports accumulate.
  2. Read the reports. Identify every legitimate source and confirm each one has aligned SPF or DKIM. Fix the ones that don't. That's the real work.
  3. Move to p=quarantine. Optionally ramp with pct=25, then 50, then 100. Keep watching for legitimate mail landing in spam.
  4. Move to p=reject. Once quarantine has been quiet and your pass rate is steady near 100%, go to full enforcement.

Don't skip the middle. Publishing p=reject before your sources authenticate is the single most common way to block your own transactional and marketing mail. The reports exist so you don't have to guess.

Build and read the record

You can assemble a valid policy record with the DMARC record generator, then, once reports start arriving, drop them into the DMARC report reader to see exactly which sources are ready for the next policy step. For the full picture of how the tags fit together, see our SPF, DKIM, DMARC & BIMI guide, discover how to audit incoming data using DMARC aggregate reports, and handle subdomain inheritance via DMARC sp= subdomain policies.

Frequently Asked Questions

What is the safest way to transition from p=none to p=reject?

Start with 'p=none' to monitor XML aggregate reports and identify legitimate sending services. Once aligned, progress to 'p=quarantine; pct=25', gradually ramp to 'pct=100', and finally promote the policy to 'p=reject'.

Can I apply quarantine to only a percentage of failing emails?

Yes. The 'pct=' tag specifies the percentage of failing messages to which the policy applies (e.g. 'p=quarantine; pct=20;'). The remaining 80% fall back to the next lower policy (monitoring).

Does p=none protect my domain from spoofing or phishing?

No. 'p=none' is strictly an observational policy mode. Mailbox providers deliver failing emails normally to recipient inboxes and only send aggregate telemetry reports to your 'rua' address.

What happens if an email passes SPF but fails DMARC alignment?

Under DMARC, a message fails authentication if neither SPF nor DKIM aligns with the visible 'From:' domain. If your policy is 'p=reject', receiving mailboxes will reject the message even if the raw SPF check passed.

Know when you're ready to enforce

Read your DMARC aggregate reports in plain English and see which sources are holding you back from p=reject.

Open the DMARC report reader
Sources & Primary References:

Reviewed by Philippe KAM · Last updated: Jul 18, 2026

PK

Philippe KAM

Founder & Lead Engineer at Emailens

Building next-generation email preview and QA infrastructure for developers. Focused on reverse-engineering rendering engines across Outlook (Word MSO & New Outlook), Gmail, and Apple Mail to eliminate email rendering bugs before dispatch.