← Back to the security guide
Email Spoofing ProtectionMedium risk
DMARC policy isn't enforced yet
What does this mean?
You have a DMARC record, but its policy is set to "none," which means spoofed email is still delivered to inboxes as normal — you're only collecting reports, not actually blocking anything yet.
What are the potential impacts?
- Reports are being collected, but spoofed email using your domain is still delivered to inboxes exactly as if it were legitimate — the visibility exists, but there's no actual protection yet.
- Attackers who've discovered your domain has DMARC in monitor-only mode may specifically target it, since it signals "authentication configured, but not enforced."
- Every day at p=none is a day a phishing campaign impersonating you could succeed, even though the infrastructure to stop it is one policy change away.
How to fix it
Once you've reviewed a few weeks of DMARC reports and confirmed your legitimate email sources (your email provider, any marketing or CRM tools) are all passing, update the policy to p=quarantine (spoofed mail goes to spam) or ideally p=reject (spoofed mail is rejected outright).
Want to see whether this actually affects your site? Run a free scan — no signup required.
Run a free scan