When an email fails DMARC authentication checks, what happens next depends entirely on the DMARC policy the domain owner has published. Under a none policy, the message is delivered as normal but the failure is logged. Under quarantine, it typically lands in the spam folder. Under reject, the receiving mail server refuses to accept the message entirely.
DMARC policy enforcement is the mechanism that gives domain owners real control over how their sending domain is used and abused. The policy you publish is a direct instruction to receiving mail servers, and those servers are expected to follow it.
The sections below unpack each stage of that process, from why legitimate emails sometimes fail to how you read the reports that tell you what went wrong.
What does a DMARC policy actually do with a failing email?
A DMARC policy tells the receiving mail server what action to take when an incoming message fails both SPF and DKIM alignment checks. The policy is published as a DNS record on your domain and contains one of three instructions: none, quarantine, or reject. The receiving server reads that instruction and acts accordingly, then sends a report back to the address you specify.
DMARC works by checking alignment, not just authentication. A message passes DMARC when either the SPF-authenticated domain or the DKIM-signing domain aligns with the domain in the visible From header. If neither aligns, the message fails, and the policy kicks in.
The policy also controls reporting. Even at the none level, you can instruct servers to send aggregate reports (RUA) and forensic reports (RUF) so you have visibility into what is happening with your domain before you enforce anything.
Why do legitimate emails sometimes fail DMARC checks?
Legitimate emails fail DMARC checks most commonly because of forwarding, third-party sending services, or misconfigured authentication records. When a message is forwarded, the original SPF record no longer matches the new sending server, and if DKIM is not in place, there is no fallback mechanism to pass alignment.
Other common causes include:
- Third-party senders not added to SPF: Marketing platforms, CRMs, and transactional email services all send on your behalf. If their sending infrastructure is not authorized in your SPF record, those messages will fail.
- DKIM not configured on a sending service: Many platforms require you to add a DKIM key to your DNS manually. If that step was skipped, the messages have no DKIM signature to align.
- SPF record over the 10 DNS lookup limit: SPF has a hard limit of 10 DNS lookups. Exceeding it causes SPF to fail permanently, which breaks DMARC alignment for every message that relies on SPF alone.
- Subdomain misalignment: A message sent from a subdomain may not align with the organizational domain in the From header if strict alignment is configured.
These failures are not signs of malicious activity. They are configuration gaps, and they are exactly what DMARC reporting is designed to surface before you move to enforcement.
What happens to emails under a DMARC ‘none’ policy?
Under a DMARC none policy, emails that fail authentication checks are delivered normally. The none policy carries no enforcement instruction, so receiving mail servers treat the message exactly as they would without a DMARC record in place. The only difference is that failures are logged and reported back to you.
The none policy is best understood as a monitoring phase. It lets you map out every source sending email from your domain, identify authentication gaps, and understand your traffic patterns before you enforce anything. Skipping this phase and jumping straight to quarantine or reject is one of the most common causes of legitimate email being blocked.
A none policy does not protect your domain from spoofing or phishing. Anyone can send a message using your domain in the From header and it will still be delivered. The value at this stage is purely informational: you are gathering the data you need to enforce safely.
What’s the difference between DMARC quarantine and reject?
The key difference between DMARC quarantine and reject is what the receiving server does with a failing message. Under quarantine, the message is accepted but redirected to the recipient’s spam or junk folder. Under reject, the receiving server refuses to accept the message at all, and it is never delivered.
DMARC quarantine
Quarantine is the intermediate enforcement level. It gives you real protection against spoofed messages reaching inboxes while still allowing you to recover if a legitimate sending source was misconfigured. Recipients can still find quarantined messages in their spam folder, and your team can investigate any unexpected failures before they escalate.
DMARC reject
Reject is the strongest DMARC enforcement level and the ultimate goal for most domains. When a failing message hits a server with a reject policy, the server issues a 5xx error and the message bounces. It is never delivered, never quarantined, and never visible to the recipient. This provides the strongest protection against domain spoofing and phishing, but it also means any legitimate email from an unauthenticated source is permanently lost.
How do DMARC failure reports show what went wrong?
DMARC failure reports give you a structured record of which messages failed authentication checks, which sending sources were involved, and which policy action was applied. There are two report types: aggregate reports (RUA), which provide a summary of all DMARC activity across a reporting period, and forensic reports (RUF), which contain details of individual failing messages.
Aggregate reports are the more practical tool for most teams. They show you the sending IP addresses that are using your domain, the volume of messages from each source, and whether those messages passed or failed SPF and DKIM. By reviewing these reports regularly, you can identify unauthorized senders, spot legitimate services that need authentication fixes, and track your progress as you move toward enforcement.
Forensic reports go deeper, often including message headers and sometimes content snippets. They are useful for diagnosing specific failures but are not universally supported by all receiving mail servers, and some organizations limit their use for privacy reasons.
Reading raw DMARC reports in XML format is not practical at scale. Most teams use a reporting tool or platform to parse and visualize the data in a readable format, which makes it far easier to act on what the reports reveal.
Should you move straight to a DMARC reject policy?
No, you should not move straight to a DMARC reject policy. Jumping directly to reject without a monitoring phase risks blocking legitimate email from sending sources that have not yet been authenticated. The standard approach is to start at none, analyze your aggregate reports, fix authentication gaps across all your sending sources, then move to quarantine before finally reaching reject.
The timeline for this progression varies depending on how many sending sources your domain has and how complex your email infrastructure is. A simple setup with one or two sending services can move through the stages relatively quickly. A large organization with dozens of third-party senders, internal mail servers, and legacy systems may need several months to audit and fix everything before enforcement is safe.
The risk of moving too fast is real. If a critical transactional email service or a marketing platform is not yet authenticated, moving to reject will silently drop those messages. Recipients will not receive them, and depending on your setup, you may not immediately know why. Taking the time to reach full visibility at the none stage before enforcing protects both your deliverability and your sender reputation.
How Email Industries helps with DMARC policy implementation
Getting DMARC right across the full enforcement journey, from none to reject, requires more than just publishing a DNS record. We help organizations work through every stage of that process, making sure authentication is solid before enforcement is applied. Here is what we bring to the table:
- DMARC record setup and configuration: We make sure your DMARC record is correctly structured, with the right policy level, reporting addresses, and alignment settings for your domain.
- Aggregate report analysis: We review your RUA reports to identify every sending source using your domain and flag any that are failing authentication.
- SPF and DKIM remediation: We work through each sending service to ensure SPF authorization and DKIM signing are properly configured before you move to enforcement.
- Policy progression guidance: We guide you from none to quarantine to reject at a pace that protects your legitimate email throughout the process.
- Ongoing monitoring: Authentication is not a one-time fix. We provide continuous oversight so new sending sources are caught and addressed before they cause failures.
If your domain is stuck at none, approaching enforcement for the first time, or experiencing unexpected failures after tightening your policy, explore our Deliverability Assurance Packages or browse our full range of services to find the right level of support. We are happy to take a look at where things stand and help you move forward with confidence, so feel free to get in contact with us to start the conversation.
Related Articles
- What is BIMI and how does it work in email?
- What is a DMARC policy and how does it work?
- What happens if your DKIM setup is misconfigured?
- What should my DMARC policy be?
- What services are included in full service email marketing?
- Can a poorly planned email platform migration hurt your revenue?
- What are the most common mistakes made during email platform migrations?
- What should you do before migrating to a new email service provider?
- How are full service email agencies adapting to AI and automation?
- How long does a domain warmup take?
- How do agencies create email opt-in forms?
- How do agencies ensure CAN-SPAM compliance?
- Which industries benefit most from email deliverability agencies?
- How do agencies remove domains from spam blacklists?
- How do email advertising agencies create effective campaigns?


