DMARC p=reject.In stages.Without losing mail.
DMARC Manager takes every domain from p=none via p=quarantine to p=reject. The policy is raised only when the reports support it. With automation it is rolled back the same day delivery drops.
Why many domains stay at p=none
A stricter policy discards mail. Switching too early loses legitimate mail, and it is noticed late.
p=none does not protect
As long as the policy only observes, receivers keep delivering forged mail. The record alone prevents no spoofing.
The average is misleading
Thirteen clean days and one bad day give a good average. On exactly that one day legitimate mail would have been lost.
Switching by hand
Every level is a DNS change that someone has to plan, set and verify. With many domains it is left undone.
No way back planned
When a new sending service is added, delivery breaks. Without monitoring this is noticed only through complaints.
How DMARC Manager raises the policy
One fixed rule, traceable for every domain.
1. Observe
At least fourteen days with sufficient message volume. Below that the system makes no statement.
2. Measure the weakest day
The day with the lowest rate counts, not the mean. The card names rate and date.
3. Raise one level
From p=none to p=quarantine, then to p=reject. Levels are never skipped.
What safeguards the enforcement
DMARC Manager is available as an add-on to every suite and is billed per domain.
Enforcement card per domain
Current level, observed days, weakest day and the reason if the next level is not yet supported.
Rollback when delivery drops
With automation switched on, the domain goes back one level as soon as the rate drops. A single bad day is enough.
Automatic or with approval
Automation is switchable per domain and off by default. Without it every level is approved individually.
DNS decides
The published record is the starting point. A policy that is already stricter is never weakened by raising.
History of levels
Every change is recorded with time and reason in the history and in the audit log.
Set via delegation
If the domain points to the zone maintained by Conbool, the level is set without touching your DNS.
Guided enforcement and switching by hand
The difference lies in the yardstick and the way back.
Conbool DMARC Manager | Switching by hand | |
|---|---|---|
| Yardstick for the next level | Weakest day in the observation period | Average or gut feeling |
| Minimum observation | Fourteen days with sufficient volume | Not defined |
| Rollback | With automation after one bad day | After complaints |
| Change in DNS | Via delegation without touching the provider | Every level by hand |
| Evidence | History and audit log per domain | Depends on your own documentation |
| Many domains | The same rule for every domain | Effort grows with every domain |
As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.
FAQ on introducing p=reject
How long does the path to p=reject take?
Why does the weakest day count?
Is pct used for the rollout?
What happens when a new sending service is added?
Does Conbool need access to our DNS?
Does the rollback remain when the booking ends?
Related solutions
DMARC E-Mail-Authentifizierung
SPF, DKIM und DMARC korrekt ausrichten — Schritt für Schritt zu p=reject.
DMARC Record erstellen
Den DMARC-TXT-Record richtig aufbauen — alle Tags und der sichere Weg zu p=reject.
DMARC-Monitoring
Berichte auswerten und sehen, wer im Namen der Domäne sendet.
Hosted DMARC und SPF
Einmal delegieren, Einträge dauerhaft pflegen lassen.
EasyDMARC-Alternative
DMARC-Auswertung aus der EU, ohne US-Cloud und mit Aktivschutz.
dmarcian vs. EasyDMARC
Die gängigen DMARC-Tools im Vergleich — und wo Conbool DMARC steht.
Phishing- & Spoofing-Schutz
DMARC stoppt Domain-Spoofing — kombiniert mit aktiver Phishing-Abwehr.
CEO-Fraud-Schutz
Gefälschte Absenderdomains bei BEC und CEO-Fraud zuverlässig blocken.
DANE und TLSA
DNSSEC-verankerte Transportverschlüsselung als Ergänzung zur DMARC-Authentifizierung.
MTA-STS
Erzwungene TLS-Verschlüsselung für den Transport, ergänzend zu SPF, DKIM und DMARC.
TLS-RPT
Reporting über fehlgeschlagene TLS-Verbindungen, ergänzend zu MTA-STS und DANE.
Conbool MailGuard
Aktiver Inbound-Schutz, der DMARC-Erkenntnisse direkt durchsetzt.
From p=none to p=reject, level by level.
DMARC Manager is available as an add-on to every suite and is billed per domain.