How do I move DMARC from p=none to enforcement safely?

Gradually, using your own reports as the evidence. Rushing it is how legitimate mail gets lost:

  • Collect reports at p=none first - a few weeks of aggregate reports show every service sending as you.
  • Authorise the legitimate senders - your mail provider, invoicing system, booking platform, marketing tool.
  • Step up in test mode, not by percentage - the pct tag was removed from the DMARC standard in 2026 (RFC 9989); publish the stricter policy with t=y and receivers keep applying the level below it while you watch the reports.
  • Then move to reject once the reports show only forgeries failing.

The whole process is a few weeks of watching and a few minutes of DNS edits.