Skip to main content

What is DMARC filtering?

Written by Remy

1. What is the DMARC protocol?

1.1 What is DMARC?

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a technology that helps domain owners protect their emails against identity spoofing and phishing.

It allows them to define rules for how unauthenticated emails — those that fail DKIM and SPF checks — should be handled, thereby reducing the risk of attacks.

1.2 What is DKIM?

DKIM (DomainKeys Identified Mail) is a system that adds a digital signature to emails sent from a domain.

This signature allows receiving mail servers to verify that the email actually comes from the expected sender and has not been altered in transit. This improves security and reduces the risk of email spoofing.

1.3 What is SPF?

SPF (Sender Policy Framework) is a mechanism designed to help prevent fraudulent emails by specifying which servers are authorized to send emails on behalf of a given domain.

If an email is sent from an unauthorized server, it may be marked as suspicious or rejected.

2. How does DMARC filtering work in Mailinblack?

If the sender has configured DMARC in their DNS zone, Mailinblack can apply DMARC filtering.

The system checks whether the email is compliant by performing DKIM and SPF checks.

These checks include:

  • DKIM check: Verifies the integrity of the DKIM signature using the key published on the sender's domain.

  • DKIM alignment check: Verifies that the domain in the DKIM header (d=) matches the domain in the From header.

  • SPF check: Verifies that the sending mail server's IP address is included in the sender domain's DNS zone.

  • SPF alignment check: Verifies that the envelope domain matches the domain in the From header.

2.1 What are the possible DMARC filtering results?

A DMARC check can result in either Pass or Fail, depending on the SPF and DKIM checks performed.

The possible combinations are shown below:

DKIM Pass

DKIM Alignment Pass

SPF Pass

SPF Alignment Pass

DMARC Result

Yes

Yes

Yes

Yes

Pass

Yes

Yes

No

No

Pass

Yes

No

Yes

Yes

Pass

Yes

No

No

No

Fail

No

Yes

Yes

Yes

Pass

No

Yes

No

No

Fail

No

No

Yes

Yes

Fail

No

No

No

No

Fail

What happens if the DMARC result is "Fail"?

When the DMARC result is Fail, the email is generally quarantined and categorized as Spam.

Which policy can the sender apply?

The final action taken when authentication fails depends on the policy defined by the sender in their DMARC record (p=).

The following options can be used:

  • NONE: No action is taken.

  • QUARANTINE: The email is placed in the Spam category.

  • REJECT: The email is placed in the Spam category.

2.2 How should the different filtering results be interpreted?

For DMARC to pass, either SPF or DKIM must pass together with its corresponding alignment check.

Pass: DMARC is considered successful if DKIM passes with alignment, or if SPF passes with alignment.

Examples of Pass results when tracing an email:

Fail: DMARC fails if neither DKIM with alignment or SPF with alignment passes.

Examples of Fail results when tracing an email:

3. How can I allow a sender even if the DMARC check fails?

From the Protect interface, click Settings, then General settings.

Go to the SPF and DMARC verification exclusions setting.

You can add an exclusion based on:

Future emails matching the added exclusions will no longer be categorized as Spam, even if the SPF and/or DMARC check fails.

Did this answer your question?