Solution · DMARC Manager

DMARC p=reject.In stages.Without losing mail.

DMARC Manager takes every domain from p=none via p=quarantine to p=reject. The policy is raised only when the reports support it. With automation it is rolled back the same day delivery drops.

Why many domains stay at p=none

A stricter policy discards mail. Switching too early loses legitimate mail, and it is noticed late.

p=none does not protect

As long as the policy only observes, receivers keep delivering forged mail. The record alone prevents no spoofing.

The average is misleading

Thirteen clean days and one bad day give a good average. On exactly that one day legitimate mail would have been lost.

Switching by hand

Every level is a DNS change that someone has to plan, set and verify. With many domains it is left undone.

No way back planned

When a new sending service is added, delivery breaks. Without monitoring this is noticed only through complaints.

How DMARC Manager raises the policy

One fixed rule, traceable for every domain.

1. Observe

At least fourteen days with sufficient message volume. Below that the system makes no statement.

2. Measure the weakest day

The day with the lowest rate counts, not the mean. The card names rate and date.

3. Raise one level

From p=none to p=quarantine, then to p=reject. Levels are never skipped.

What safeguards the enforcement

DMARC Manager is available as an add-on to every suite and is billed per domain.

Enforcement card per domain

Current level, observed days, weakest day and the reason if the next level is not yet supported.

Rollback when delivery drops

With automation switched on, the domain goes back one level as soon as the rate drops. A single bad day is enough.

Automatic or with approval

Automation is switchable per domain and off by default. Without it every level is approved individually.

DNS decides

The published record is the starting point. A policy that is already stricter is never weakened by raising.

History of levels

Every change is recorded with time and reason in the history and in the audit log.

Set via delegation

If the domain points to the zone maintained by Conbool, the level is set without touching your DNS.

Guided enforcement and switching by hand

The difference lies in the yardstick and the way back.

 
Conbool DMARC Manager
Switching by hand
Yardstick for the next level
Weakest day in the observation period
Average or gut feeling
Minimum observation
Fourteen days with sufficient volume
Not defined
Rollback
With automation after one bad day
After complaints
Change in DNS
Via delegation without touching the provider
Every level by hand
Evidence
History and audit log per domain
Depends on your own documentation
Many domains
The same rule for every domain
Effort grows with every domain

As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.

FAQ on introducing p=reject

How long does the path to p=reject take?
At least fourteen observed days per level. The total duration depends on how quickly all legitimate sending sources pass SPF and DKIM.
Why does the weakest day count?
Because it is the day on which legitimate mail would have been lost. A mean hides it.
Is pct used for the rollout?
No. Receivers apply pct randomly per message. The same sender is then delivered once and not the next time, and nothing can be learned from that.
What happens when a new sending service is added?
If it fails SPF and DKIM, the rate drops. With automation the domain goes back one level. The source appears in the analysis and can be corrected.
Does Conbool need access to our DNS?
No. With delegation a one-time record points to a zone maintained by Conbool. Without delegation the card names the level and you set it yourself.
Does the rollback remain when the booking ends?
Yes. The booking applies to raising a level. The rollback of the automation remains as a safety net.

From p=none to p=reject, level by level.

DMARC Manager is available as an add-on to every suite and is billed per domain.