← Back to the security guide
Email Spoofing ProtectionMedium risk

DMARC policy isn't enforced yet

What does this mean?

You have a DMARC record, but its policy is set to "none," which means spoofed email is still delivered to inboxes as normal — you're only collecting reports, not actually blocking anything yet.

What are the potential impacts?

  • Reports are being collected, but spoofed email using your domain is still delivered to inboxes exactly as if it were legitimate — the visibility exists, but there's no actual protection yet.
  • Attackers who've discovered your domain has DMARC in monitor-only mode may specifically target it, since it signals "authentication configured, but not enforced."
  • Every day at p=none is a day a phishing campaign impersonating you could succeed, even though the infrastructure to stop it is one policy change away.

How to fix it

Once you've reviewed a few weeks of DMARC reports and confirmed your legitimate email sources (your email provider, any marketing or CRM tools) are all passing, update the policy to p=quarantine (spoofed mail goes to spam) or ideally p=reject (spoofed mail is rejected outright).

Want to see whether this actually affects your site? Run a free scan — no signup required.

Run a free scan