p=none: the DMARC policy that looks compliant and stops nothing

Ask anyone in email security which domain is the easiest to impersonate and you will hear the same answer: the one with no DMARC record. True enough. But we think there is a worse one, and there are far more of them: the domain that published DMARC with p=none — and stayed there.
This is our position, and it is not the consensus. Here is the reasoning, written for people who run email and for people who merely depend on it.
First, what DMARC actually decides (skip this if you know)
Everything about DMARC gets easier once you accept one thing: your DMARC policy is not about the mail you receive. It is about mail that claims to come from you.
When a message says From: [email protected], the server receiving it — Gmail, Microsoft 365, a supplier's filter, your own mail server — looks up your domain's DMARC record in DNS and finds two things: how to check whether the message is genuinely yours (SPF and DKIM, aligned with your name), and what you want done if that check fails. That second part is the policy:
| Your record says | What a receiver does with a forgery in your name |
|---|---|
p=reject | Refuses it. The forgery never arrives. |
p=quarantine | Accepts it, files it to junk. |
p=none | Delivers it normally, and sends you a report about it later. |
| (no record) | Nothing to look up. Receivers fall back on their own judgement. |
So DMARC is an instruction you publish for the whole world about outgoing mail in your name. That world includes your own company: when someone forges [email protected] to write to [email protected], it is your own Microsoft 365 or Google Workspace that reads your record and follows it.
p=none therefore means exactly this: "if a message in my name is a forgery, deliver it anyway and tell me about it."
The case that no DMARC is worse — and why it is weaker than it looks
The argument is straightforward: with no record there is no policy at all, so receivers have nothing to apply. Anyone can send as that domain.
That was more true five years ago than it is today. Receivers have stopped treating "no DMARC" as neutral. Gmail and Yahoo require DMARC from anyone sending in volume; Microsoft followed; filters everywhere count the absence of a record as a weakness and hold or refuse mail that also fails SPF or DKIM. A domain with no DMARC and weak authentication is already distrusted — its forgeries often do less damage in practice, because they were suspicious to begin with.
Nobody is reassured by a domain with no DMARC. That is the point.
Why p=none is the better domain for an attacker
Now take the same domain a week after it published v=DMARC1; p=none; rua=mailto:.... Three things changed, and all three help the attacker.
1. It now passes the paperwork. Vendor questionnaires, cyber-insurance forms, compliance scanners, most "check your DMARC" tools: they ask is there a record? and the answer is yes. The box gets ticked. Nobody follows up.
2. The forgeries still go through — by instruction. p=none is not a weaker filter; it is an explicit request to receivers: do not act on this. A forged message fails DMARC alignment exactly as it would have before, and the receiver does exactly what your record told it to do: deliver.
3. The forgery can look clean everywhere else. Here is the part that matters to the technical reader. An attacker who sends from their own infrastructure gets SPF pass and DKIM pass — for their sending domain, in headers few people read. Only DMARC compares those results to the name in the From: line, and only DMARC fails. If the sending IP has a clean reputation, the message carries no known-bad link, and the text avoids the urgency and wire-transfer clichés that spam filters look for, then the only signal left is "DMARC failed on a domain that asked us to do nothing about it." Many filters will not act on that. Some cannot.
Put those together and p=none gives an attacker a name that reads as trustworthy on every checklist while still being fully forgeable — including toward the domain's own employees, whose own mail server will follow the same instruction.
We are not describing an exotic attack. We are describing the ordinary invoice-fraud email, sent well.
"But p=none is the right first step"
It is. We have written before about why monitoring matters, and nothing here changes that. p=none exists so you can turn on the reports, discover every system that sends in your name — the payroll provider, the CRM, the printer nobody remembers — and fix their authentication before you start rejecting anything. Skipping that step breaks legitimate mail. Do not skip it.
The problem is not the step. It is that so many organizations never take the next one. In our August study of 296 Quebec organizations, 24% were spoofable — no record, or p=none — and a further 48% had stopped at p=quarantine. We routinely find p=none records untouched for years. A monitoring phase that never ends is not monitoring. It is an open door with a compliance sticker on it.
How long should you stay at p=none?
Our position: as short as you can make it. For most organizations that is weeks, not months. For a small one, it is an afternoon.
If you are a small organization, a home-based business or a one-person shop, you probably send email from two or three places: your mail provider (Microsoft 365 or Google Workspace), maybe a newsletter tool, maybe an invoicing or booking app. That is the whole list. Finding those sources, fixing SPF and DKIM for each one and moving to p=reject is a few hours of work — a day at most. Our Email Source Map does the finding for you: it reads your DMARC reports and tells you exactly what sends in your name and what to fix. Any competent IT consultant can do the rest in the same afternoon. There is no reason for a small business to sit at p=none for a month.
If you are larger — a marketing platform, a CRM, a payroll provider, ticketing, and the printer nobody remembers — plan it, but plan it in weeks:
- Turn on aggregate reports on day one (
rua=), and read them with a tool rather than by hand. - Within two to four weeks you should know every legitimate source. Most organizations have fewer than ten. Fix SPF and DKIM for each one. Our guide to what actually needs to change is the short version.
- Move to
p=quarantineas soon as your known sources pass. Forgeries go to junk instead of the inbox, and a legitimate source you missed is recoverable. - Move to
p=rejectwhen the reports are quiet. That is the setting that makes forging your name pointless. - Tell your own people to treat the
p=noneweeks as an exposure window. Confirm any change of bank details by phone, at a number you already had. That advice never expires, but it matters most while your name is forgeable.
Whatever your size: if you have been at p=none for longer than a quarter, you are not in a monitoring phase any more. You are the supplier in somebody else's fraud story.
Check where you stand
It takes a minute and it is free: check your domain here. The result shows your current policy and what the next step is. If it says p=none, look at the date you published it — and decide whether you are still monitoring, or just parked.
Want to read this later? Email it to yourself.
Stay ahead of email threats
Get our latest DMARC, SPF, and email-security guides in your inbox. No spam — unsubscribe anytime.
We only use your email to send blog updates. One click unsubscribes you.