DMARC is monitoring only (p=none)
URGENTWhat it means
p=none tells receivers to deliver mail that fails authentication anyway. You can see spoofing in the reports, but nothing is stopped, example.com is still fully spoofable today.
How to fix it
Review your aggregate reports until only known senders pass, then move to p=quarantine, and finally p=reject.
Check your own domain
This page describes the condition. To find out whether your domain has it, run the DMARC test or the full checkup, which examines every record at once.
Understand it properly
This page covers one condition. For the whole picture, The DMARC guide, from a first record to enforcement, or start at the Health Library.
Where this comes from
We judge this against RFC 9989 section 4.7. Every finding on this site cites the specification behind it so you can check the work rather than take our word for it.
Other DMARC conditions
DMARC_P_NONE
Every fix on this site is yours to implement. If you would rather someone did it, I take this work directly.