How DMARC Applies to Subdomains (and the sp= Tag)
Attackers love unguarded subdomains. Here's how DMARC's sp= tag works, how policy inheritance plays out, and how to lock down domains you don't even send from.
By default, subdomains inherit the root domain's policy (p=...). The sp= tag allows you to specify a separate policy for all subdomains. This is crucial for protecting inactive or parked subdomains from spoofing (e.g. p=none; sp=reject;) while you audit the root domain.
One record, a whole tree of domains
DMARC is published once, at _dmarc.acme.com. That single record governs the organizational domain and every subdomain under it, unless a subdomain publishes its own DMARC record. The policy that applies to a subdomain is decided in a specific order.
How the subdomain policy is chosen
When a receiver evaluates mail from news.acme.com, it resolves the policy like this:
- Does
_dmarc.news.acme.comexist? If the subdomain publishes its own DMARC record, that record wins outright. - Otherwise, look at the organizational domain's record. If
_dmarc.acme.comsets ansp=tag, that value is used for the subdomain. - If there's no
sp=, the subdomain inheritsp=. The root policy applies to subdomains by default.
So sp= is the lever for treating subdomains differently from the root domain (stricter or looser) without publishing separate records for each one.
A worked example
v=DMARC1; p=quarantine; sp=reject; rua=mailto:dmarc@acme.com- Mail from
acme.comthat fails DMARC is quarantined (thep=value). - Mail from any subdomain (
news.acme.com,totally-made-up.acme.com) that fails is rejected (thesp=value).
This is a common and sensible shape: a slightly forgiving policy on the domain you actively send from, and a hard sp=reject on subdomains, most of which you never send from at all.
Why unused subdomains are a target
Attackers know that teams focus DMARC on their main domain. If your root is at p=reject but you never set sp=, a subdomain still inherits reject, good. But the mistake to avoid is a weaker root or a missing policy that leaves subdomains open. Spoofers will happily send "invoices" from billing.acme.com if nothing stops them.
The defensive move for domains you never send mail from is a locked-down record (no authorized senders and a hard fail) so nothing can pass:
SPF: v=spf1 -all
DMARC: v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc@acme.comAlignment and subdomains
One more subtlety: relaxed alignment (the default, adkim=r/aspf=r) treats a subdomain as aligned with its organizational domain. So mail from mail.acme.com with a From: of acme.com aligns fine under relaxed mode. Switch to strict (s) and the domains must match exactly, which often breaks legitimate subdomain senders. Unless you have a specific reason, keep alignment relaxed.
Put it into practice
Set your sp= when you build the record with the DMARC record generator, then confirm subdomain mail is behaving as expected by reading your aggregate reports in the DMARC report reader. The header_from in each row tells you which domain the mail claimed to be from. New to the tags? Start with DMARC policy modes, decode your aggregate telemetry with our DMARC report guide, and review core infrastructure setup in our SPF, DKIM & DMARC guide.
Frequently Asked Questions
What does the sp= tag in a DMARC record do?
The 'sp=' tag defines the policy for subdomains. If omitted, all subdomains inherit the root domain's 'p=' policy. Setting 'sp=reject' on a root domain with 'p=none' allows you to monitor the main domain while blocking spoofed subdomains immediately.
How does DMARC policy inheritance work for subdomains?
When an email arrives from a subdomain (e.g. mail.acme.com), the receiver first checks for a DMARC TXT record directly on '_dmarc.mail.acme.com'. If none exists, it searches up the DNS tree to '_dmarc.acme.com' and applies the 'sp=' (or 'p=') rule.
Can an individual subdomain have its own DMARC record?
Yes. Any subdomain can publish its own DMARC record at '_dmarc.sub.domain.com', which completely overrides any inherited 'p=' or 'sp=' rules from the parent domain.
What is relaxed vs strict alignment (aspf and adkim)?
Under relaxed alignment (the default), subdomains align with their organizational domain (e.g., mail.acme.com aligns with acme.com). Under strict mode ('aspf=s; adkim=s;'), the domain in the From header must exactly match the authentication domain.
Cover your subdomains, not just your domain
Build a record with the right sp= policy and see every sending source (root and subdomain) in your reports.
Open the DMARC record generator- •IETF RFC: IETF RFC 7489 Section 6.6.3: Subdomain Policy Inheritance
- •IETF RFC: IETF RFC 7960: Interoperability Issues in Email Authentication
- •Google Support: Google Workspace Admin: Subdomain DMARC Management
- •Cloudflare Learning Center: Cloudflare: Understanding Email Authentication & Subdomains
Reviewed by Philippe KAM · Last updated: Jul 18, 2026
Building next-generation email preview and QA infrastructure for developers. Focused on reverse-engineering rendering engines across Outlook (Word MSO & New Outlook), Gmail, and Apple Mail to eliminate email rendering bugs before dispatch.