Quick start for your business

A friendly, step-by-step guide to getting your first domains set up in DMARCER, from adding them through to a full enforcement policy that blocks spoofed mail without stopping your own legitimate senders.

Published 22 Jul 2026 0

New to DMARCER? Welcome. This guide walks you through getting your first domains protected, from adding them right through to a full enforcement policy. The goal is simple: stop other people sending email that pretends to come from your domain, without ever blocking your own genuine senders. Work through the sections below in order and you will be in good shape.

What the quick start covers

DMARCER looks after the email security DNS records for your domains (SPF, DKIM, DMARC, DNSSEC, MTA-STS and TLS-RPT), reads the DMARC and TLS reports that mailbox providers send back, and gives each domain a security score so you can see exactly where it stands. The quick start takes you from an empty account to a domain that is actively monitored and ready to move towards blocking spoofed mail.

  • Add your domains and choose how each one is monitored.
  • Verify ownership so DMARCER can manage and report on the domain.
  • Read the security score and the per-record status checks.
  • Use your DMARC reports to confirm every legitimate sender passes.
  • Move through the enforcement journey to quarantine, then reject.

Step 1: Add your domains

Open Domain Management and click Add Domains in the toolbar above the table. The Add New Domains panel lets you add several domains at once: type or paste them into the Domains box, one per line (for example example.com). DMARCER checks the format and skips anything that is invalid or already in your account, explaining why next to each one so you can correct it rather than starting over.

Before you add them, set the options that apply to the whole batch:

  • Monitoring Region: the region whose mailbox receives this domain's DMARC and TLS reports. It is pre-selected from your account country, so you can usually leave it as it is.
  • Licence type: choose Standard for domains that actively send mail (full monitoring), or Parked for domains you own but do not send from. A parked domain is watched so that any sending activity at all is spotted and you are alerted straight away; if it ever does start sending (an MX record or a sending SPF record appears), DMARCER moves it to Standard for you automatically.
  • Customer (MSPs) or Business area (Enterprise): assign the domains to the right client or internal team. Business accounts do not see this option, as there is only one customer.

All domains in a single batch share the same Licence type and region, so if you need to mix them, add your Standard and Parked domains in separate batches. Click Add Domains to finish.

Step 2: Verify domain ownership

A new domain shows as not validated until you prove you control its DNS. Open the row's actions menu and choose Validate ownership to open the Verify Domain Ownership panel. It gives you a DNS TXT record to publish at the root of the domain: the Name is _DMARCER. followed by your domain, and the Value is a unique code shown in the panel. Use the copy buttons to avoid typos.

Publish that TXT record with your DNS provider. Validation then runs on its own, or you can click Recheck Now once the record is live. The check is made directly against DNS, so there is no waiting around for caches to update. If the domain is linked to a supported DNS integration, you can publish the record with a single click from the same panel instead of adding it by hand.

Ownership matters because the SPF and DMARC builders, along with MTA-STS and TLS-RPT, only become available once a domain is validated. Until then those columns simply show a greyed-out dash.

Step 3: Read the security score and status checks

Each validated domain gets a security score from 0 to 100 with a band, and these roll up into a per-customer and per-account average so you can see your overall standing at a glance. The score rewards real protection rather than just having a record in place, and it ignores anything that does not have data yet, so a brand new domain with no sending history is not unfairly marked down. Parked domains are scored against their own checklist, so a domain you correctly hold but do not use scores well without needing DKIM or MTA-STS it has no use for.

In the Domain Management grid, the status icons for SPF, DKIM, DMARC, DNSSEC, MTA-STS, TLS-RPT and the Score are all clickable. Each one opens the settings or detail view for that record, so you can fix issues right from the grid. Tackle the weakest items first to raise the score.

Step 4: Confirm your senders from DMARC reports

Once your DMARC record is published with a reporting address (the RUA address), mailbox providers begin sending aggregate reports to your Monitoring Region mailbox. These reports list every source sending email that claims to be your domain, and whether each one passed SPF and DKIM alignment. Reports usually take 24 to 72 hours to start arriving after a receiver first sees your record, so a little patience here is normal.

Use this information to make sure your legitimate senders (your mail platform, marketing tools, helpdesk, invoicing systems and so on) all pass alignment before you tighten the policy. This is the single most important step for avoiding self-inflicted delivery problems: if you tighten the policy before a real sender is passing, that sender's mail will be quarantined or rejected.

Step 5: Move through the enforcement journey

The Enforcement page lists every validated domain, sorted by how ready it is to advance, so the domains needing your attention sit at the top. The Readiness column shows Ready to advance, Almost ready, Not yet, or End state (enforced). Click a row to open Domain Management with the DMARC wizard ready for that domain.

The journey climbs a series of stages: Not configured, Monitoring (p=none), Quarantine (eased in at 10, 25, 50 then 100 percent), and Reject (eased in at 10, 25, 50 then 100 percent). Publishing Monitoring (p=none) is always safe, as it only watches and never affects delivery. Each later step is offered once your reports show enough passing mail over a set period, so you move forward based on real evidence rather than guesswork.

  • Start at Monitoring (p=none) and let the reports build a picture of who sends for you.
  • Fix any legitimate sender that is failing alignment before moving on.
  • Advance into Quarantine, raising the percentage as your readiness allows.
  • Finish at Reject 100 percent, the end state, where spoofed mail is blocked outright.

Common pitfalls

  • Adding the ownership TXT record on the wrong host. It belongs at _DMARCER. plus your domain, at the root of the domain, not on a subdomain.
  • Expecting reports straight away. Aggregate DMARC reports typically take 24 to 72 hours to start once receivers see your record, so an empty report view early on is perfectly normal.
  • Advancing past Monitoring before every real sender passes. Only tighten once the reports confirm your legitimate mail is aligned.
  • Mixing Standard and Parked domains in one batch. The Licence type and region apply to the whole batch, so add different kinds separately.
  • Trying to set up SPF, DMARC or MTA-STS before ownership is validated. Those options stay switched off (a greyed-out dash) until the domain is verified.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles