Most domains that deploy DMARC never make it past p=none. Monitoring mode feels safe — nothing breaks, reports flow in, the compliance checkbox looks ticked. But at p=none, DMARC protects nothing: spoofed mail is still delivered, and your domain remains an open target.
The reason teams stall is fear, and the fear is legitimate. Moving to enforcement without preparation does break mail — usually the forgotten third-party senders: the CRM, the billing system, the survey tool someone connected in 2019. The answer isn't to stay at none. It's to enforce in stages.
Run at p=none for at least 4–6 weeks and treat aggregate reports as a census. Every source that sends on your domain's behalf must be identified and classified: legitimate and aligned, legitimate but misaligned, or unauthorized.
Misaligned legitimate senders are what break at enforcement. For each one, establish SPF alignment (the return-path domain must match), DKIM alignment (the signing domain must match), or ideally both. Third-party platforms almost always support custom DKIM signing — it's usually a DNS record away.
Move to p=quarantine with pct=10, then raise the percentage weekly while watching reports. Any legitimate mail caught in the ramp shows up in reports before it becomes a business incident.
Once quarantine at 100% runs clean for two or more weeks, move to p=reject. Then close the common loophole: set an explicit sp= subdomain policy, or attackers simply spoof anything.yourdomain.com instead.
GoDMARC turns this exact process — inventory, alignment, staged enforcement — into a dashboard your team can run, with typosquatting alerts and threat mapping included.
Explore GoDMARCAt p=reject your domain can no longer be spoofed at scale, mailbox providers treat your mail with more trust, and you unlock eligibility for BIMI — your verified logo in the inbox, which is where brand trust becomes visible.
Enforcement isn't risky. Unplanned enforcement is risky. Staged, monitored, aligned — it's one of the highest-leverage projects an email team can ship.
I've run DMARC rollouts from none to reject without a single lost legitimate email.