Enforcement
The difference between monitoring, quarantine and reject, and what enforcement actually protects.
Why isn't p=quarantine enough?
At p=quarantine, forged mail is usually sent to spam rather than blocked, so it still reaches the recipient and can still be opened. It is a useful staging step, not the destination. Only p=reject actually stops impersonating mail from being delivered. This is also what the mailbox providers advise: Microsoft states plainly that the goal is to reach a p=reject policy for all of your domains, treating p=none and p=quarantine as testing stages on the way there.
What changes at p=reject?
At p=reject, any message that fails authentication for your domain is refused at the door instead of delivered. That is the point where impersonation of your domain genuinely stops. The whole rollout is about getting to p=reject without also rejecting your own legitimate mail.
We already have DMARC, now what?
Check the policy you are actually publishing. A record at p=none only monitors and protects nothing. The work is moving from p=none to p=reject safely: identify every legitimate sender, fix the ones that fail, and confirm from real data that enforcement will not break anything before you switch it on.
Keep reading
Next enforcement decision
See where your own domain stands.
Check your domain free, then reach full enforcement without breaking legitimate email.