Back to blog

Deliverability

DMARC p=none vs Quarantine vs Reject for Cold Email Domains

FRFolderly ResearchDeliverability and cold email strategy teamJuly 20, 20264 min read

Choose a DMARC policy safely by understanding monitoring, alignment, staged enforcement, reporting, and the difference between minimum compliance and protection.

Use DMARC p=none to collect reports while you discover legitimate senders, then move through quarantine toward reject only after SPF or DKIM alignment is reliable. p=none can satisfy the published minimum for some high-volume provider rules, but it does not ask receivers to block spoofed mail. Enforcement is the protection goal; staged monitoring is the safe path.

Start with the entity overview, What is DMARC for cold email?, then use the Email Authentication Analyzer to identify which records and policy values to verify with your DNS provider.

The three DMARC policies

Policy Receiver request for mail that fails DMARC Best use
p=none Take no policy action based on DMARC; send reports Discovery and monitoring
p=quarantine Treat failing mail as suspicious Staged enforcement
p=reject Reject failing mail Mature enforcement after validation

DMARC passes when at least one supported authentication method passes and aligns with the visible From domain. A message can have a passing SPF result but still fail DMARC if the authenticated SPF domain does not align. The same principle applies to DKIM.

What p=none does and does not do

p=none turns on visibility. Aggregate reports show which systems send on behalf of the domain and whether SPF, DKIM, and alignment pass.

It is useful when:

  • the domain has never published DMARC
  • several sales, marketing, support, and transactional tools send mail
  • ownership of old senders is unclear
  • a team needs evidence before enforcement

It does not tell receivers to quarantine or reject failures. Treat it as a diagnostic stage, not a permanent security achievement.

Google permits p=none for its bulk-sender DMARC requirement. Microsoft also states that at least p=none is required for covered high-volume Outlook senders. Those are minimum delivery requirements, not claims that monitoring alone stops impersonation.

When to use quarantine

Quarantine is the controlled middle step. It asks receivers to treat failing messages as suspicious, often by routing them away from the inbox.

Move to quarantine when:

  1. every legitimate sending service is inventoried
  2. SPF and DKIM pass consistently
  3. at least one method aligns for each legitimate stream
  4. forwarding and third-party edge cases are understood
  5. report ownership is assigned

Use a limited percentage if your deployment plan needs a smaller enforcement sample, then increase it as reports stay clean. Do not assume every receiver will apply the requested action identically.

When to use reject

Reject is the strongest published request. It is appropriate when legitimate mail is aligned, reporting is stable, and the organization is prepared to investigate failures quickly.

Before reject:

  • test sales engagement mail
  • test CRM notifications
  • test billing and transactional systems
  • test support platforms
  • test website form and application mail
  • check subdomain policy behavior
  • confirm vendors are not sending with an unaligned visible From domain

One missed business-critical sender can turn a security improvement into lost mail. Change policy with the people who own every mail stream, not only the cold email tool.

A staged DMARC rollout

Use this sequence:

  1. publish SPF and enable DKIM for each legitimate sender
  2. publish DMARC at p=none with aggregate reporting
  3. review reports until legitimate sources and alignment are understood
  4. fix or remove unknown and misaligned senders
  5. move a controlled share to quarantine
  6. expand quarantine while monitoring failures
  7. move to reject when legitimate mail remains clean
  8. continue reviewing reports after enforcement

The SPF, DKIM, and DMARC guide explains how the three controls interact. The 2026 provider requirements brief explains why p=none appears in minimum requirements.

Does p=none improve cold email deliverability?

p=none can help a domain meet published DMARC requirements and provides reports that expose authentication problems. It does not create positive reputation or guarantee inbox placement. Relevant targeting, low complaints, list quality, stable volume, and message quality still matter.

Can I move directly from no DMARC to p=reject?

Technically yes, but it is risky when legitimate mail streams are unknown or misaligned. A staged rollout from monitoring to enforcement gives the team evidence, time to fix vendors, and a controlled way to avoid rejecting valid business mail.

Sources and next step

Primary sources: DMARC.org's deployment overview, Google email sender guidelines, and Microsoft's high-volume sender requirements.

Review the policy controls in the Email Authentication Analyzer, confirm the live record through your DNS provider, then test the message itself in the AI Cold Email Deliverability Checker.

#DMARC policy#p=none#p=quarantine#p=reject
FR

Folderly Research

Deliverability and cold email strategy team

Folderly Research studies cold email quality, sender reputation, and deliverability patterns across outbound workflows so teams can ship sharper messages without guessing.

Next step

Check the draft before the campaign goes live.

Run copy, AI-template, compliance, complaint-budget, and sender setup guidance in the public Folderly checker.

Related articles

Continue with practical email guidance.

DMARC p=none vs Quarantine vs Reject | Folderly