Email deliverability
What is DMARC, and which record should you use?
DMARC is one DNS record that tells mail servers what to do with email that claims to come from your domain but fails SPF and DKIM. It stops fake invoices and "urgent payment" emails sent in your company's name, and Gmail and Yahoo now expect it.
How it works
When Gmail receives a message from accounts@yourcompany.com, it checks two things. Does SPF or DKIM pass? And does the passing domain match the From address? If not, it looks up _dmarc.yourcompany.com and follows your policy.
The record
Name: _dmarc
Type: TXT
Value: v=DMARC1; p=quarantine; rua=mailto:dmarc@syncgaze.in
| Tag | Meaning |
|---|---|
p=none | Only watch and report. Nothing is blocked. Good for your first week if other services send mail as you. |
p=quarantine | Mail that fails goes to spam. A sensible default once your real mail passes. |
p=reject | Mail that fails is refused. The strongest protection. |
rua=mailto:… | Where daily reports go. These show every server sending as your domain. |
pct=50 | Optional: apply the policy to only part of the failing mail while you roll it out. |
A safe rollout
- Make sure SPF and DKIM pass for every service that sends as you (your mailbox, billing software, website forms). Check your domain.
- Start with
p=noneand aruaaddress, then read the reports for a week or two. - Move to
p=quarantine, and later top=reject.
On SyncGaze Mail
The suggested DMARC record sends reports to SyncGaze. Your dashboard then shows who is sending mail as your domain, including anyone faking it, without you reading raw XML reports.
Verify and test
- Wait 5–30 minutes after saving. Most changes show up within minutes, but some take up to a few hours.
- Go back to dashboard.syncgaze.in → Domains and click Verify. Each record turns green when SyncGaze can see it.
- Run a free check on mail.syncgaze.in/check. It reads your MX, SPF, DKIM and DMARC records and explains anything still missing.
- Send a test email to a Gmail address and open Show original. It should show
SPF: PASS,DKIM: PASSandDMARC: PASS.
Rather not touch DNS yourself?