DMARC email record
A DMARC record on every email domain the school or trust holds, which helps stop criminals sending emails that appear to come from it. It should move to a policy of reject, and nothing on the website is involved.
Check this on my websiteWho it applies to
- Published on
- School and trust websites
- School type
- Academies and maintained schools
- School stage
- All stages, from early years to sixth form
- Does not apply to
- No school types are excluded
When is it due?
- Renewal
- No fixed date
The official sources set no renewal date. Keep it accurate whenever it changes.
What's needed
Publish a DMARC record in the DNS for the school's email domain, starting at p=none and moving to quarantine or reject (guidance says schools should).
What it must contain
4 parts- Has a DMARC record on every domain, including parked domainsShould
- Publishes the DMARC record as a TXT recordShould
- Sets the DMARC policy to rejectShould
- Gives an address for DMARC aggregate reportsGood practice
What the official sources say
Set out in 3 official sources:
NCSC: implement a DMARC policy of none
All of your domains, including parked domains , should have DMARC records in place, regardless of whether the domain is used for email or not.
Should§ Page 7 of 14 > Implement a DMARC policy of ‘none’ (introduction)
Your DMARC record name is: _dmarc.yourdomain.gov.uk It should be configured as a TXT record, with an initial value similar to this: v=DMARC1;p=none;rua=mailto: [email protected]
Should§ Page 7 of 14 > How to create the DMARC record
Show 4 more from this source
We recommend you apply DMARC gradually, iterating your DMARC configuration over time. Start by implementing a DMARC policy of ‘ none ’. You can view this policy as a ‘monitoring phase’, during which the DMARC processing tool you selected in Step 1 collects and reports on which systems and services are sending emails from your domains. This does not interfere with your email traffic in any way.
Good practice§ Page 7 of 14 > Implement a DMARC policy of ‘none’ (introduction)
“rua” is a comma separated list of URI(s) for aggregate report delivery. This report contains details of the emails being sent from your domain, including whether they passed or failed the SPF and DKIM authentication checks. You can include up to 2 email addresses for which to send the aggregated data reports. If you’re eligible to use Mail Check and do, you need to include our email address, to ensure that you send the aggregated data to Mail Check – details are provided within Mail Check.
Good practice§ Page 7 of 14 > How to create the DMARC record
In this ‘monitoring only phase’ we recommend keeping your DMARC record as simple as shown above. You do not need to add additional ‘DMARC tags’ (see https://tools.ietf.org/html/rfc7489#page-17 ) at this stage.
Good practice§ Page 7 of 14 > How to create the DMARC record > Note
Semi-colons are used to separate the tags. Commas are used to separate multiple email addresses (where more than one is used). You do not need a semi-colon (or full stop) at the end of the DMARC record.
Good practice§ Page 7 of 14 > How to create the DMARC record
NCSC: reject spoof emails (DMARC p=reject)
As soon as you are confident DKIM and SPF are continuing to work correctly, you should move to a DMARC policy of ‘reject’ .
Should§ Page 12 of 14 > 5. Reject spoof emails (introduction)
Having a DMARC policy of ‘ reject ’ on all of your domains is the best way to prevent spoofing of your email. The goal for this section is to help you get to that point.
Good practice§ Page 12 of 14 > 5. Reject spoof emails (introduction)
Show 2 more from this source
An example record applied to 50% of your email looks like this: v=DMARC1;p=reject;sp=reject;fo=1;pct=50;rua=mailto: [email protected]
Good practice§ Page 12 of 14 > Iterating a DMARC record
We recommend you now update your DMARC record to a policy of p=reject and apply it to a small percentage of your email.
Good practice§ Page 12 of 14 > Iterating a DMARC record
Email security and anti-spoofing (SPF, DKIM, DMARC)
Domain-based Message Authentication, Reporting and Conformance (DMARC) allows you to set a policy for how receiving email servers should handle email which doesn’t pass either SPF or DKIM checks. This includes untrusted emails, which should be discarded. DMARC also generates reports, which you can use to understand how your email is being handled.
Good practice§ Page 1 of 14 > introduction, point 1 (In summary)
Questions schools ask
Does every school have to publish the DMARC email record?
The official sources we check set no requirement for academies. The official sources we check set no requirement for maintained schools.
When does the DMARC email record need to be published?
Renewal: No fixed date. The official sources set no renewal date. Keep it accurate whenever it changes.
What must the DMARC email record include?
Has a DMARC record on every domain, including parked domains; Publishes the DMARC record as a TXT record; Sets the DMARC policy to reject; Gives an address for DMARC aggregate reports.
Where does the requirement for the DMARC email record come from?
It is set out in NCSC: implement a DMARC policy of none, NCSC: reject spoof emails (DMARC p=reject) and Email security and anti-spoofing (SPF, DKIM, DMARC).
Changes to the official sources
The sources for this item do not publish dated change notes. Their current versions are listed above.
We last checked these sources on 21 September 2026.
Is this on your school's website?
We check your site the way an inspector or a parent would find it: page by page, against the official wording of each requirement. If it's there, you get the page and the words we found. If it isn't, you get every place we looked.
Check this one requirement free, or scan your whole site against every requirement.
Official wording that does not apply to schools (1)
Within 24 hours of publishing your records you’ll start receiving email reports from major email recipient domains . These will come to the two addresses you specified in your DMARC record.
Official sources last checked 21 September 2026 · register version 1.0.4