DMARC
DMARC is a DNS policy built on SPF and DKIM that tells receiving servers what to do with unauthenticated email from your domain.

What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email policy you publish as a TXT record at _dmarc.yourdomain.com. It builds on top of SPF and DKIM and tells receiving mail servers what to do with messages that claim to come from your domain but fail authentication. An email passes DMARC when it passes SPF or DKIM and the authenticated domain aligns with the visible sender domain in the From header (alignment).
Why does DMARC matter?
DMARC stops attackers from spoofing your domain in phishing emails, protecting both your customers and your sender reputation. Since February 2024, Google and Yahoo also require bulk senders (roughly 5,000+ messages per day) to publish a DMARC record — without one, your order confirmations and newsletters risk landing in spam or being rejected.
Common use cases
- Monitor first: Start with
p=noneand aruaaddress to see who sends mail using your domain before tightening up. - Enforcement: Move to
p=quarantineorp=rejectonce SPF and DKIM are correct, so spoofed mail is filtered or blocked. - Meeting sender requirements: Satisfy the Google/Yahoo rules for your transactional emails and campaigns.
- Deliverability debugging: Use aggregate reports to find sources that fail authentication.
Shopify perspective
When you authenticate a sending domain in Shopify, you get four CNAME records that cover SPF and DKIM for your store’s mail. DMARC is not included — you add the _dmarc TXT record yourself at your DNS provider. Remember your other senders too (e.g. Klaviyo or support tools), so everything sends aligned before you move to p=reject.