30/03/2026
Many businesses say they’ve “done DMARC.”
But when you check the policy?
p=none.
That means:
• Spoofed emails still get delivered
• Attackers can still impersonate your domain
• You’re only receiving reports
There are three DMARC policies:
p=none → Monitor only
p=quarantine → Send failing mail to spam
p=reject → Block failing mail entirely
Only one actually stops spoofing.
If your policy never moved past monitoring,
your protection never started.
We explain when to use each (and how to move safely) in the latest blog.