Skip to content
← Back to the guide

DMARC rollout from p=none to p=reject

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

DMARC rollout from p=none to p=reject

How to roll out DMARC enforcement progressively — the journey from monitoring to enforced anti-spoofing.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

What does DMARC p=reject actually do?

It tells receiving mail servers to reject messages claiming to be from your domain that fail both SPF and DKIM alignment. Combined with reporting, it stops direct domain spoofing of your brand — the prerequisite for Gma…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

How long does a DMARC rollout take?

Two to three months for most organisations: publish p=none with reporting, spend four to six weeks identifying every legitimate sender from the aggregate reports and fixing their SPF/DKIM, move to p=quarantine with a pe…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

Do I need a DMARC reporting tool?

Aggregate reports are XML files sent to the rua address — unreadable at volume by hand. A reporting service (free tiers exist) or Microsoft's DMARC reports in the Defender portal turn them into sender lists you can act…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

Small domain, few sending sources, all already passing

Reasonable pct step: 50 → 100 in two steps · Why: Little left to break; a slow crawl adds time without adding safety

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Several sending sources, one still unconfirmed

Reasonable pct step: 10 → 25 → 50 → 100 · Why: Each step is a chance to catch a source the reports didn't clearly flag

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

High-volume transactional mail (invoices, notifications) riding on the domain

Reasonable pct step: 5 → 10 → 25 → 50 → 100, held for a full billing cycle at each step · Why: A quarantined invoice email that a customer never sees is a support and revenue problem, not just an inbox nuisance

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

Domain used mostly for internal mail, external senders are a small fraction

Reasonable pct step: 25 → 100 · Why: Internal mail via Exchange Online authenticates cleanly by default; external risk is the only real unknown

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/dmarc-rollout

Slide 8Download PNG

Auto-generated from DMARC rollout from p=none to p=reject. This page is not indexed and isn't part of the guide itself.