Get started
Email deliverability

What is DMARC, and which record should you use?

DMARC is one DNS record that tells mail servers what to do with email that claims to come from your domain but fails SPF and DKIM. It stops fake invoices and "urgent payment" emails sent in your company's name, and Gmail and Yahoo now expect it.

How it works

When Gmail receives a message from accounts@yourcompany.com, it checks two things. Does SPF or DKIM pass? And does the passing domain match the From address? If not, it looks up _dmarc.yourcompany.com and follows your policy.

The record

Name: _dmarc Type: TXT Value: v=DMARC1; p=quarantine; rua=mailto:dmarc@syncgaze.in
TagMeaning
p=noneOnly watch and report. Nothing is blocked. Good for your first week if other services send mail as you.
p=quarantineMail that fails goes to spam. A sensible default once your real mail passes.
p=rejectMail that fails is refused. The strongest protection.
rua=mailto:…Where daily reports go. These show every server sending as your domain.
pct=50Optional: apply the policy to only part of the failing mail while you roll it out.

A safe rollout

  1. Make sure SPF and DKIM pass for every service that sends as you (your mailbox, billing software, website forms). Check your domain.
  2. Start with p=none and a rua address, then read the reports for a week or two.
  3. Move to p=quarantine, and later to p=reject.

On SyncGaze Mail

The suggested DMARC record sends reports to SyncGaze. Your dashboard then shows who is sending mail as your domain, including anyone faking it, without you reading raw XML reports.

Verify and test

  1. Wait 5–30 minutes after saving. Most changes show up within minutes, but some take up to a few hours.
  2. Go back to dashboard.syncgaze.in → Domains and click Verify. Each record turns green when SyncGaze can see it.
  3. Run a free check on mail.syncgaze.in/check. It reads your MX, SPF, DKIM and DMARC records and explains anything still missing.
  4. Send a test email to a Gmail address and open Show original. It should show SPF: PASS, DKIM: PASS and DMARC: PASS.
{# Help Assistant is self-injected by static/help/assistant.js (loaded in base.html). Nothing to render here — kept so the base.html include stays valid. #}