Skip to content

CERT-Cyberross · 5 min read

p=quarantine is not enforcement

Why a partial DMARC policy provides far less protection than the dashboard suggests, and what the percentage tag actually does.

Published

  • Email
  • DMARC
  • Hardening

A DMARC record reading p=quarantine; pct=25 is frequently presented internally as 'DMARC is deployed'. What it actually means is that receiving mail servers are asked to apply the policy to a quarter of failing messages, and to do nothing at all about the other three quarters.

The pct tag exists for a good reason: it lets you ramp enforcement while you find the legitimate senders you forgot about — the invoicing platform, the ticketing system, the marketing tool nobody told IT about. It is a migration aid, not a destination.

Organisations get stuck at partial enforcement because the ramp has no owner and no deadline. The aggregate reports arrive, nobody parses them, and the record stays where it was set two years ago.

The remedy is unglamorous: parse the aggregate reports, enumerate every legitimate sender, bring each into alignment, then move to p=reject; pct=100. Until that last step, an attacker spoofing the domain succeeds most of the time.

Next step

See what an attacker sees

We map your external attack surface the way an adversary does — exposed assets, leaked credentials, impersonation domains. No agent, no access, no cost.

30 min

A scoping call, with an engineer rather than a sales rep.

What it costs

Nothing, and there is no sequence afterwards. If we are not the right fit we will say so and suggest who is.

Under attack now?

Do not use this form. The hotline is answered around the clock and reaches a duty analyst directly.