Moving to enforcement Step 10 of 30

The 30-day review: moving to p=reject

Reject waits for 30 days of reports and a month at enforced quarantine. What the advisor checks, and how to take the final step safely.

Updated

p=reject asks receivers to refuse mail that fails DMARC outright. It’s the policy that actually stops someone sending as your domain — and because rejected mail is gone rather than sitting in a junk folder, the advisor asks for more evidence before it recommends it.

What the advisor needs before it recommends reject

The domain must be enforcing p=quarantine (with t=y removed). Then:

Check Test quarantine Enforce quarantine Test and enforce reject
Days of reports at least 14 at least 30 at least 30
Messages observed at least 100 at least 100 at least 500
Mail passing DMARC at least 95% at least 95% at least 98%
Persistent failing sources none none none
Days at enforced quarantine — — at least 30 (to start testing reject)

Why thirty days. Monthly senders — invoicing, statements, payroll — don’t appear in a two-week window. Recommending p=reject after a good fortnight is how a billing system gets discovered in production. Thirty days of reports means a month has rolled over at least once.

As before, these are days covered by reports, counted over the last 90 days, and any source that keeps failing blocks the recommendation by name.

Days at enforced quarantine is a separate clock: it starts when we first see your record at p=quarantine without t=y. Unlike quarantine, reject can’t be quietly undone — a refused message never reaches anyone’s junk folder — so the advisor waits for a month of quarantine actually acting on your mail. Anything someone finds in their junk folder in that month is a sender to fix while it’s still recoverable. Until then, the Next step panel shows it as, for example, “12 of 30 days at p=quarantine”.

The advisor’s numbers are minimums. Organisations with quarterly senders (a quarterly newsletter, a tax run) should give it 60 to 90 days of reports. From the first report, most domains reach p=reject in three to six months.

Before you take the step

Go back to Sending sources one more time and look at:

  • Partly aligned sources. Anything still failing some of the time will be refused that part of the time.
  • SPF only in the domain page’s Alignment breakdown. That mail passes today but fails when it’s forwarded — and at p=reject, forwarded mail that fails is refused. Where the service supports DKIM, turn it on.
  • Anything new. A sender added since you moved to quarantine has had less time in the reports.

When the advisor is satisfied, the Next step panel says Ready to test p=reject.

The Next step panel recommending p=reject in testing mode

Test, then enforce

The same two-step change as quarantine:

  1. Publish p=reject with t=y, keeping everything else:

    v=DMARC1; p=reject; t=y; rua=mailto:d1…@reports.dmarcloop.com
    
  2. Leave it at least a week. The panel shows Ready to enforce p=reject while the evidence holds.

  3. Remove t=y:

    v=DMARC1; p=reject; rua=mailto:d1…@reports.dmarcloop.com
    

The panel then reads Fully enforcing. Nothing further to tighten.

If your record has an sp= tag (the policy for subdomains) or an np= tag (the policy for subdomains that don’t exist), check those too: a domain at p=reject with sp=none still leaves its subdomains open.

Next

Staying at p=reject.

Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.