# DMARC Policy — PostFrame — EternalEngine

DMARC tells receiving mail servers what to do when emails fail SPF or DKIM checks, plus aggregate reporting on who sends email as your domain.

[Back to Domain Verification](https://eternalengineos.io/features/postframe/domain-verification/)DMARC

Domain Security

# DMARC Policy

PostFrame generates a starter DMARC record for your domain — p=none with aggregate reports to an address you own — and checks it alongside SPF and DKIM. Tighten it to quarantine or reject once the reports look clean.

[Start free](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Domain verification overview](https://eternalengineos.io/features/postframe/domain-verification/)

## Policy and Reporting

Policy enforcement

Choose none, quarantine or reject for mail that fails authentication — PostFrame's generated record starts at p=none so nothing legitimate is dropped while you review reports

Aggregate reports

Receiving servers send XML reports to the rua address in your record, so you can see every server sending as your domain

Alignment checking

DMARC verifies that the From domain aligns with SPF and DKIM domains — preventing sophisticated spoofing

Gradual enforcement

Start with p=none to monitor, move to quarantine, then reject as you gain confidence in your authentication

DMARC Record

Record type

TXT

Host

_dmarc.yourdomain.com

Generated record

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Required for verification?

No — recommended. The check still reports found, missing or mismatch

## Keep exploring PostFrame

[### SPF record The include directive PostFrame asks you to publish. Open SPF record →](https://eternalengineos.io/features/postframe/domain-verification/spf/)[### DKIM signing Three CNAMEs and a 2048-bit signing key. Open DKIM signing →](https://eternalengineos.io/features/postframe/domain-verification/dkim/)[### Domain verification The whole guided setup, record by record. Open Domain verification →](https://eternalengineos.io/features/postframe/domain-verification/)

Questions

## Common questions, straight answers.

Is DMARC required to verify a domain?

No. Verification requires the ownership TXT record, the three DKIM CNAMEs, the SPF record and the bounce-domain MX and SPF. DMARC is listed as recommended and checked the same way.

Which policy should I start with?

p=none. It changes nothing about delivery and gets you the aggregate reports. Move to quarantine, then reject, once the reports show only senders you recognize.

Where do the DMARC reports go?

To the mailbox named in the rua= tag of your record — an address you own. PostFrame generates the record but does not read the reports.

How does PostFrame keep SPF aligned for DMARC?

It sets a custom bounce domain (bounce.yourdomain.com) with its own MX and SPF records, so the envelope sender is on your domain and SPF alignment passes.

## Run your business from one place.

Five plans, seventeen launch apps, one dashboard. Set up in under 5 minutes — change tiers any time.

[Start free$0 forever &bull; No card &bull; Upgrade any time](https://app.eternalengineos.io/signup?plan=free&interval=annual)[Talk to Sales](https://eternalengineos.io/contact/)

From $0 · Basic $9.95/mo · Save 20% on annual billing · Upgrade or downgrade any time
