Moving to enforcement Step 12 of 35

Staying at p=reject

Enforcement isn't the end of monitoring: the alerts that matter at p=reject, the adviser board, and what to do when you add a new sending service.

Updated

At p=reject, the Next step panel reads Fully enforcing and the domain sits in the Maintain stage. The job from here is keeping it that way: mail setups change, and a new service that sends as your domain without being set up has its mail refused.

What keeps watching

The adviser still assesses every domain daily, DNS records are still checked every six hours, and reports keep arriving. The alerts that matter most once you enforce:

  • Mail being blocked: an enforcing domain has legitimate-looking mail failing DMARC. The panel says Mail is being affected right now and names the sender under Failing now. Fix the sender; with hosted DMARC the panel also offers Step the policy back, which reopens the domain to some spoofing.
  • New sending source: a source not seen before sent meaningful volume as the domain (50 messages in its first two days).
  • Policy loosened: the published policy went down a step, perhaps by someone editing the record by hand.
  • DMARC record missing, DMARC record invalid, Reports no longer sent to us: the record that does the enforcing has changed.
  • Reports stopped: no reports for seven days.

The full list, and how to choose which reach you, is in Notifications and alerts. The weekly digest summarises every domain’s stage and what needs attention.

Adding a new sending service

Set it up before it sends, not after: publish the DKIM records the service gives you (and its SPF include, if it needs one), then turn on sending. The service’s entry in the Sender library has the steps. Within a day or two of it starting, check the domain’s Sources: it should be in Compliant.

If DKIM is hosted, add the service’s selector under DKIM on the DNS records tab; see DKIM keys and BIMI.

The adviser board

Adviser board, in the left sidebar, shows every domain by stage, with what blocks it, how long it has been there and its pass rate. It’s assessed daily. Use it to see at a glance that every domain is in Maintain, and which aren’t yet.

The adviser board: each domain by stage, with its next step and blockers

Domains that don’t send mail

A parked domain is the easiest one to spoof, because nobody watches its mail. Lock it down: p=reject, an SPF record that authorises nobody, a null MX and revoked DKIM.

Next

Hosted records.

Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.