InboxAudit

DMARC p=none is doing nothing

A p=none policy monitors and reports but blocks nothing. Spoofed mail using your domain is still delivered.

What causes it

  • The rollout stopped at the monitoring stage, which is where most DMARC deployments stall permanently.

How to fix it

Use the rua reports to confirm every legitimate sender authenticates, then move to p=quarantine, then p=reject. Until you do, you get visibility but no protection.

Check your domain

Also searched for: p=none meaning, dmarc policy none, dmarc not enforcing.