Moving to enforcement Step 11 of 35

The 30-day review: moving to p=reject

Reject waits for 30 days of reports, 98% passing and a month at enforced quarantine. What the adviser checks, and how to take the final step safely.

Updated

p=reject asks receivers to refuse mail that fails DMARC outright. It’s the policy that actually stops someone sending as your domain, and because rejected mail is gone rather than sitting in a junk folder, the adviser asks for more evidence before it recommends it.

What the adviser needs

The domain must be enforcing p=quarantine (with t=y removed). Then:

Check Test quarantine Enforce quarantine Test reject Enforce reject
Days of reports at least 14 at least 30 at least 30 at least 30
Messages observed at least 100 at least 100 at least 500 at least 500
Mail passing DMARC at least 95% at least 95% at least 98% at least 98%
Persistent failing sources none none none none
Time at the previous step 30 days at enforced quarantine 7 days testing reject

As before, days are days covered by reports in the last 90; the pass rate and failing sources are judged over the last 30 days; and a source that keeps failing blocks the step by name.

Days at enforced quarantine is a separate clock. It starts the first day the adviser sees your record at p=quarantine without t=y. Reject can’t be quietly undone (a refused message never reaches anyone’s junk folder), so the adviser waits for a month of quarantine actually acting on your mail. Anything someone finds in their junk folder in that month is a sender to fix while it’s still recoverable. Until then, What’s in the way shows, for example, “12 of 30 days at p=quarantine”.

The adviser’s numbers are minimums. If you have quarterly senders, such as a quarterly newsletter or a tax run, give it 60 to 90 days of reports.

Before you take the step

Look at the domain’s Sources once more:

  • Known sender, failing and Unknown or threat: anything of yours still failing will be refused.
  • Sources that pass on SPF aligned but not DKIM aligned. That mail passes today but fails when it’s forwarded, and at p=reject forwarded mail that fails is refused. Where the service supports DKIM, turn it on.
  • Anything new. A sender added since you moved to quarantine has had less time in the reports. The adviser also emails a New sending source alert when one appears.

When the checks pass, the panel says Ready to test p=reject.

Ready to test p=reject: example.com after 46 days at enforced quarantine

If you enforced today shows what reject would have refused over the last 30 days. Forwarded mail from mailing lists is usually most of it; see Identify your sending sources.

Test, then enforce

The same two-step change as quarantine:

  1. Publish p=reject with t=y, keeping everything else. In test mode, receivers treat it as p=quarantine:

    v=DMARC1; p=reject; t=y; rua=mailto:rua-…@dmarcloop.net
    
  2. Leave it at least seven days. The panel shows “3 of 7 days testing p=reject” until then, and Ready to enforce p=reject when the evidence holds.

  3. Remove t=y:

    v=DMARC1; p=reject; rua=mailto:rua-…@dmarcloop.net
    

With hosted DMARC, Apply this step makes each change; with a self-managed record, edit it at your DNS host and choose Check now. The panel then reads Fully enforcing, and the domain moves to Maintain.

If your record has an sp= tag (the policy for subdomains) or an np= tag (subdomains that don’t exist), check those too: a domain at p=reject with sp=none still leaves its subdomains open. In the DMARC editor they are Subdomains (sp) and Subdomains that don’t exist (np).

Next

Staying at p=reject.

Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.