DMARC p=reject setup, SPF and DKIM
I take domains to DMARC p=reject with DKIM aligned, without losing legitimate mail on the way.
What I set up
Everything a receiving server checks.
- SPF, trimmed to the hosts that really send.
- DKIM signing on every sending service, aligned with the From domain.
- DMARC with reporting, tightened to p=reject as the reports come clean.
- MTA-STS and TLS reporting.
- BIMI, once the policy allows it.
How I do it
I list every sender first: the mailbox provider, the website, the newsletter tool, anything that sends as the domain. I fix alignment for each one.
I publish DMARC with reporting, read the aggregate reports, and tighten the policy only when every legitimate source passes.
In production
The email domain for Solent Gay Men's Chorus is at p=reject with DKIM aligned. So is this one. The policy for passionfruit.design is read live from DNS and shown in the Receipts.
Questions people ask
Will p=reject block our own mail?
Not if every sender is aligned first. That is what the reporting stage is for.
What about forwarding and mailing lists?
Forwarding breaks SPF but not DKIM. That is why I align DKIM on every sender and do not rely on SPF alone.
Work like this
-
Solent Gay Men's Chorus
Registered charity. The whole platform, built and run by me.
In plain English
-
Email security
Stop people sending fake email from your address. I set up your domain so fakes are rejected and your real email still arrives. No new provider needed.
Tell me what you need
A few lines about the project is enough. I read every message myself. I meet people face to face within about 30 miles of Portsmouth, and work with organisations anywhere in the UK.
Or email hello@passionfruit.design, or call or WhatsApp 07385 509278.