Skip to main content

Enforcement

The difference between monitoring, quarantine and reject, and what enforcement actually protects.

At p=quarantine, forged mail is usually sent to spam rather than blocked, so it still reaches the recipient and can still be opened. It is a useful staging step, not the destination. Only p=reject actually stops impersonating mail from being delivered. This is also what the mailbox providers advise: Microsoft states plainly that the goal is to reach a p=reject policy for all of your domains, treating p=none and p=quarantine as testing stages on the way there.

At p=reject, any message that fails authentication for your domain is refused at the door instead of delivered. That is the point where impersonation of your domain genuinely stops. The whole rollout is about getting to p=reject without also rejecting your own legitimate mail.

Check the policy you are actually publishing. A record at p=none only monitors and protects nothing. The work is moving from p=none to p=reject safely: identify every legitimate sender, fix the ones that fail, and confirm from real data that enforcement will not break anything before you switch it on.

Next enforcement decision

See where your own domain stands.

Check your domain free, then reach full enforcement without breaking legitimate email.