---
title: "Switch From p=quarantine to p=reject in DMARC? | DMARC Report"
description: "When and how to move your DMARC policy from p=quarantine to p=reject without breaking legitimate mail."
image: "https://dmarcreport.com/og/blog/switch-from-pquarantine-to-preject-in-dmarc.png"
canonical: "https://dmarcreport.com/blog/switch-from-pquarantine-to-preject-in-dmarc/"
---

Quick Answer

Domains compliant with DMARC are less vulnerable to becoming targets of phishing-based cyberattacks than the ones not using it. Domains without DMARC enforcement are 4.75x more likely to be the target of spoofing versus domains with DMARC enforcement. Switching from p=quarantine to p=reject is the final step in DMARC enforcement, but timing and prerequisite checks matter to avoid breaking legitimate mail.

Related: [Free DMARC Checker](/tools/dmarc-checker/) 

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=undefined%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Switch%20From%20p%3Dquarantine%20to%20p%3Dreject%20in%20DMARC%3F&url=undefined%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=undefined%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F "Share on Facebook") [ ](https://reddit.com/submit?url=undefined%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F&title=Switch%20From%20p%3Dquarantine%20to%20p%3Dreject%20in%20DMARC%3F "Share on Reddit") [ ](mailto:?subject=Switch%20From%20p%3Dquarantine%20to%20p%3Dreject%20in%20DMARC%3F&body=Check out this article: undefined%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F "Share via Email") 

![DMARC](https://media.mailhop.org/dmarcreport/images/2023/10/dmarc-report-2922.jpg) 

## Try Our Free DMARC Checker

Validate your DMARC policy, check alignment settings, and verify reporting configuration.

[ Check DMARC Record → ](/tools/dmarc-checker/) 

[![](https://media.mailhop.org/dmarcreport/images/2023/10/dmarc-report-4560.jpg)](https://dmarcreport.com/)

[Get DMARC Enforcement in 90 Days. Guaranteed. \[Click Here\]](https://dmarcreport.com/)

It’s no news that domains compliant with DMARC are less vulnerable to becoming targets of [phishing-based cyberattacks](https://portswigger.net/daily-swig/microsoft-report-unmasks-at-least-six-russian-nation-state-actors-responsible-for-cyber-attacks-against-ukraine) than the ones not using it. In fact, domains without DMARC enforcement are [4.75x](https://www.helpnetsecurity.com/2021/03/23/domains-protected-dmarc/) more likely to be the **target of spoofing** versus domains with DMARC enforcement. 

There are **3 DMARC policies** and each of them represents an action that recipients’ mail servers are instructed to take against unauthentic email sources\*\*.\*\* This blog revolves around these policies and explains which one you should set, depending upon the nature and intricacies of your business architecture and domain utility. 

## DMARC Policies: None, Quarantine, and Reject

_DMARC stands for Domain-based Message Authentication, Reporting, and Conformance._ It’s an [email authentication](/what-is-dmarc/) and security protocol that defines what to do with emails sent from your domain that **fail SPF and/or DKIM checks**. It’s such an important and result-driven security method that now it’s mandatory for [PCI DSS](/blog/mandatory-requirement-dmarc-compliance-included-in-pci-dss-version-4-0/) compliance. This is to safeguard customer details to ward off potential phishing and spoofing attacks\*\*.\*\*

_The 3 DMARC policies are none, quarantine, and reject_, so [choosing a DMARC policy](/blog/what-is-a-dmarc-policy-and-how-does-it-affect-sending-my-emails/) comes down to your domain’s readiness. You can change them as and when you want, but **monitoring DMARC reports** for your domain is always good for evaluating the right time to make these transitions. We’ll talk about this in the following sections, but let’s just quickly learn what actions do each of the DMARC policies represent-

![DMARC-benefits](https://media.mailhop.org/dmarcreport/images/2023/10/how-to-create-dmarc-record-13.jpg) 

### Monitor or None Policy (p=none)

It’s the starting point of [DMARC implementation](/blog/most-common-mistakes-to-avoid-while-deploying-dmarc/), where domain owners just monitor and evaluate the outgoing (sometimes even incoming) [email traffic](https://emailanalytics.com/email-traffic/) for both authorized and **unauthorized senders**. This phase helps them take into account how their domains are being used and if they are under the radar of malicious actors.

### Quarantine Policy (p=quarantine)

It’s the first stage of the transition from a lenient to a stricter policy. The quarantine policy tells recipients’ mailboxes to mark emails from **unauthorized senders as suspicious** and place them in [spam folders](https://www.ccleaner.com/knowledge/what-is-a-spam-folder-and-what-is-junk-mail). 

You need to take into consideration the fact that the **DMARC authentication process** also raises false positives. This means, at times, even genuine emails are misjudged as fraudulent. So, if you have set your [DMARC record](/how-to-create-dmarc-record/) to p=quarantine, then messages misidentified as phishy will still show up in the desired recipients’ mailboxes, even if they are placed in the spam folders and not primary inboxes. 

For example, you launched an [email marketing campaign](https://sproutsocial.com/insights/email-marketing/), and 10% of your emails raise **false positives** during authentication. Now, this 10% of marketing emails will still appear in the spam folders, which won’t completely **eliminate the chances** of recipients engaging with them. In this situation, your efforts won’t go to complete waste. 

Moreover, _this intermediate step prepares you for the strictest policy_. You need to be sure that, if not all, then most of your emails are passing through the **DMARC authentication checks**. In simpler words, you wait for minimum false positive instances. 

### Reject Policy (p=reject)

The [p=reject policy](/dmarc-policy/) is the **strictest policy** that directs to reject emails that **fail DMARC authentication**. It’s the ultimate goal of [DMARC](/) deployment; however, not all domain owners have the confidence to reach this level of security due to instances of false positives. Probably, that’s the reason that, as of June 2023, only [48% of banks in the UK](https://ciosea.economictimes.indiatimes.com/news/security/1-in-5-sg-banks-lack-any-form-of-email-authentication-protocol-proofpoint/102608371) have implemented the reject policy. Full [DMARC compliance](/blog/what-is-dmarc-compliance-and-how-can-you-achieve-it/) is only achieved once you reach this enforcement level.

## So, When Should You Switch From None to Quarantine to Reject?

You need to start receiving **DMARC reports regularly** to analyze the utility and susceptibility of your domain before switching policies. Start with the none policy and review the activities for a few weeks, and then you can move on to the **quarantine policy**. 

However, you can’t be swift in transitioning from quarantine to reject as it involves the risk of losing out on important conversations with clients, prospects, employees, investors, etc., due to **false positives**.

Ideally, the switch should happen in parts, which means you should start by applying the strictest [DMARC policy](/lessons/defining-a-dmarc-policy/) to only a small pre-specified percentage of emails. This is done using the **percentage tag (pct)**. 

For example: p=reject; pct=20

The above example specifies that the reject policy is applied to 20% of the outgoing messages.

_You can gradually increase the percentage as you gain confidence from monitoring DMARC reports._ 

## Step-by-Step Guide to Make a Smooth Transition

As aforesaid, you need to plan the transition to ensure your **email conversations and campaigns** aren’t getting affected; after all, you have implemented DMARC for a better [email infrastructure](https://www.voilanorbert.com/blog/email-infrastructure/) and not the other way around. 

Here, we have laid down a basic plan that you can twitch as per your business domain’s requirements and working style.

### Step 1: Start Receiving Reports

There are two types of [DMARC reports](/dmarc-report/): RUA and RUF. RUA reports include insights into email traffic, while **RUF reports** are sent when malicious activity is suspected. We automatically send these reports to the email address provided by you, eliminating the need to log into any portal. 

To start receiving these reports, you just need to add rua and ruf tags to your DMARC record.

### Step 2: Diligently Evaluate the DMARC Reports

Regularly analyze DMARC reports during the “none” policy phase to gain insights into the **sources of email traffic**. Look for anomalies, unauthorized senders, or suspicious patterns that may indicate [phishing attempts](https://www.bleepingcomputer.com/news/security/new-zerofont-phishing-tricks-outlook-into-showing-fake-av-scans/).

### Step 3: Switch to Quarantine

It’s best to make the move when only a small percentage of your emails experience [authentication failures](/blog/fix-spf-permerror-overcome-too-many-dns-lookups/). The readiness for this transition differs, depending upon the nature of the domain and **business intricacies** involved.

Leverage the benefit of the pct tag by **configuring it to a small percentage** at first. Make gradual adjustments to make the process smooth.

### Step 4: Switch to Reject

Move to the strictest policy when there are minimal instances of [false positives](https://www.nospamproxy.de/en/what-is-a-false-positive-and-what-is-a-false-negative/). Properly enforced, the Reject policy doesn’t adversely impact **email flow and deliverability**. _Delay the switching decision if important emails are still landing in spam folders_. Once you’re confident that most vital messages reach recipients’ inboxes, you can proceed to 100 percent enforcement.

![mail servers ](https://media.mailhop.org/dmarcreport/images/2023/10/dmarc-report-2134.jpg) 

## Critical Considerations for Transitioning Policies

Here’s what you need to keep in mind-

### Gradual Policy Implementation

Abrupt policy transitions give hackers the opportunity to trick recipients’ [mail servers](https://www.cloudflare.com/learning/email-security/what-is-a-mail-server/) and have **fraudulent emails** placed in the primary inboxes. _Moreso, it jeopardizes genuine communications between your company and clients or prospects on multiple levels_.

### Collaboration With Third-Party Senders

Ensure third-party senders implement [DKIM](/dmarc-fundamentals/what-is-dkim/) and [SPF](/dmarc-fundamentals/what-is-spf/) for aligning with your DMARC policy. Otherwise, genuine emails sent by them will be **misidentified as fraudulent** by recipients’ mail servers.

### Monitoring and Adjusting

Make adjustments to your policies as per your evaluation of DMARC reports.

### User Education

Communicate policy changes to internal stakeholders and educate users about the importance of DMARC in enhancing [email security](/blog/why-is-email-security-important-for-businesses-today-2/). Provide guidance on recognizing and [reporting suspicious emails](https://terranovasecurity.com/what-you-need-to-know-about-reporting-an-email-scam/).

## DMARC Report Monitoring is the Key

DMARC report monitoring is the overviewing of your domain’s email activity to identify **unauthorized and potentially fraudulent conversations**. You can also evaluate them to understand what percentage of your messages are raising false alarms. 

To get started with DMARC Reporting, [book a demo](/book-a-demo/). We’ll warn you when your domain’s [DNS configuration](https://phoenixnap.com/kb/dns-configuration) changes. We’ll even tell you when your emails aren’t sent due to deliverability issues, **security threats**, and more. Even better, you’ll get these warnings delivered straight to your inbox.

## Topics

[ DMARC ](/tags/dmarc/)[ dmarc record policy ](/tags/dmarc-record-policy/)[ email security ](/tags/email-security/)[ News ](/tags/news/) 

![Brad Slavin](https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.

[Start Free Trial](https://app.dmarcreport.com/signup?plan=free) [Check Your DMARC Record](/tools/dmarc-checker/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F) [ ](https://twitter.com/intent/tweet?text=Switch%20From%20p%3Dquarantine%20to%20p%3Dreject%20in%20DMARC%3F&url=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fdmarcreport.com%2Fblog%2Fswitch-from-pquarantine-to-preject-in-dmarc%2F) Copy 

Related Articles

- [ ![cybersecurity news](https://media.mailhop.org/dmarcreport/images/2026/04/dmarc-record-1187.jpg)  $20M Phishing Bust, Pension Scam Alert, Booking Data Breach Uncategorized ](/blog/20m-phishing-bust-pension-scam-alert-booking-data-breach/)
- [ ![dkim-selector](https://media.mailhop.org/dmarcreport/images/2026/04/dkim-selector-0370.jpg)  Best DMARC Tools for MSPs and Managed Service Providers in 2026 Uncategorized ](/blog/best-dmarc-tools-for-msps-managed-service-providers-in-2026/)
- [ ![DMARC Reporting Tool](https://media.mailhop.org/dmarcreport/images/2023/12/dmarc-office-365-11.jpg)  A Guide to Choosing the Best DMARC Reporting Tool for Your Business Uncategorized ](/blog/guide-to-choosing-best-dmarc-reporting-tool-for-business/)
- [ ![DMARC](https://media.mailhop.org/dmarcreport/images/2026/01/create-dmarc-record-9903.jpg)  How can I start protecting my G Suite email from phishing with DMARC? Uncategorized ](/blog/how-to-protect-g-suite-email-from-phishing-using-dmarc/)

## Related Articles

[  Uncategorized 5m  $20M Phishing Bust, Pension Scam Alert, Booking Data Breach  Apr 15, 2026 ](/blog/20m-phishing-bust-pension-scam-alert-booking-data-breach/)[  Uncategorized 19m  Best DMARC Tools for MSPs and Managed Service Providers in 2026  Apr 29, 2026 ](/blog/best-dmarc-tools-for-msps-managed-service-providers-in-2026/)[  Uncategorized 6m  A Guide to Choosing the Best DMARC Reporting Tool for Your Business  Dec 19, 2023 ](/blog/guide-to-choosing-best-dmarc-reporting-tool-for-business/)[  Uncategorized 12m  How can I start protecting my G Suite email from phishing with DMARC?  Jan 28, 2026 ](/blog/how-to-protect-g-suite-email-from-phishing-using-dmarc/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"DMARC Report","url":"https://dmarcreport.com","description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","publisher":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
[{"@context":"https://schema.org","@type":"BlogPosting","headline":"Switch From p=quarantine to p=reject in DMARC?","description":"When and how to move your DMARC policy from p=quarantine to p=reject without breaking legitimate mail.","url":"https://dmarcreport.com/blog/switch-from-pquarantine-to-preject-in-dmarc/","datePublished":"2023-10-04T14:03:49.000Z","dateModified":"2026-04-01T13:05:10.000Z","dateCreated":"2023-10-04T14:03:49.000Z","author":{"@type":"Person","@id":"https://dmarcreport.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://dmarcreport.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind DMARC Report, AutoSPF, Phish Protection, and Mailhop. He founded DuoCircle in 2014 and has led the company's growth to 2,000+ customers across its email security product family. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement).","image":"https://media.mailhop.org/dmarcreport/images/team/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"DMARC Report","url":"https://dmarcreport.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com","logo":{"@type":"ImageObject","url":"https://dmarcreport.com/images/dmarcreport-logo.png"},"description":"DMARC reporting and email authentication management. Monitor aggregate and forensic DMARC reports, analyze authentication results, and enforce DMARC policies across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138898167","https://www.linkedin.com/company/duocircle","https://x.com/duocirclellc","https://www.g2.com/products/dmarc-report/reviews","https://github.com/duocircle","https://www.crunchbase.com/organization/duocircle-llc","https://www.trustradius.com/products/duocircle/reviews"],"aggregateRating":{"@type":"AggregateRating","ratingValue":"4.8","reviewCount":"471","bestRating":"5","worstRating":"1","url":"https://www.g2.com/products/dmarc-report/reviews"},"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://dmarcreport.com/support/"},"knowsAbout":["DMARC","DMARC Reporting","DMARC Aggregate Reports","DMARC Forensic Reports","Sender Policy Framework","DKIM","Email Authentication","Email Security","DNS Management","Email Deliverability"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://dmarcreport.com/blog/switch-from-pquarantine-to-preject-in-dmarc/"},"articleSection":"uncategorized","keywords":"DMARC, dmarc record policy, email security, News","wordCount":1284,"image":{"@type":"ImageObject","url":"https://media.mailhop.org/dmarcreport/images/2023/10/dmarc-report-2922.jpg","caption":"DMARC","width":900,"height":600},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}]
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://dmarcreport.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://dmarcreport.com/blog/"},{"@type":"ListItem","position":3,"name":"Uncategorized","item":"https://dmarcreport.com/uncategorized/"},{"@type":"ListItem","position":4,"name":"Switch From p=quarantine to p=reject in DMARC?","item":"https://dmarcreport.com/blog/switch-from-pquarantine-to-preject-in-dmarc/"}]}
```
