How do I move DMARC from p=none to enforcement safely?
Gradually, using your own reports as the evidence. Rushing it is how legitimate mail gets lost:
- Collect reports at p=none first - a few weeks of aggregate reports show every service sending as you.
- Authorise the legitimate senders - your mail provider, invoicing system, booking platform, marketing tool.
- Step up in test mode, not by percentage - the pct tag was removed from the DMARC standard in 2026 (RFC 9989); publish the stricter policy with t=y and receivers keep applying the level below it while you watch the reports.
- Then move to reject once the reports show only forgeries failing.
The whole process is a few weeks of watching and a few minutes of DNS edits.