Setup Guides · Zoho Mail
Zoho Mail DMARC Setup: monitor first, then enforce
DMARC ties SPF and DKIM together, tells receivers what to do with mail that fails, and emails you reports on who is sending as your domain. It is the record that actually stops your domain being spoofed. Set it up in your own DNS, start in monitoring mode, and tighten to p=reject once the reports are clean. Here is the safe path.
Last updated 8 September 2026 · applies to all Zoho Mail plans with a custom domain
Zoho Mail authentication series: SPF · DKIM · DMARC
First, get SPF and DKIM passing
DMARC passes when a message aligns on SPF or DKIM (ideally both). So before you enforce anything, make sure both are set up and verified for your Zoho domain: the SPF record (include:zohomail.com) and the DKIM key (zoho._domainkey). DMARC without those underneath it has nothing to pass on.
Set it up in three steps
1Publish a monitoring record
DMARC is a TXT record in your own DNS - Zoho's Admin Console has a generator to help you compose it, but the record lives at your DNS host. Start here:
Host: _dmarc Type: TXT Value: v=DMARC1; p=none; rua=mailto:[email protected]
p=none changes nothing about how your mail is handled. It simply asks receivers to send you aggregate reports, so you can see every source sending as your domain before you enforce anything.
2Read the reports
Those reports arrive as XML from every mailbox provider - effectively unreadable by hand. Point your rua address at a monitor that turns them into plain language. Postbox DMARC Monitor parses the XML into a clear weekly view of who is sending as your domain and whether they pass SPF and DKIM alignment - so you can see, at a glance, when every legitimate sender (Zoho and any newsletter or CRM tools) is aligned and it is safe to enforce.
3Tighten the policy
When the reports show only your real senders passing, step the policy up. Give each stage a couple of weeks:
v=DMARC1; p=quarantine; rua=mailto:[email protected] ↓ v=DMARC1; p=reject; rua=mailto:[email protected]
p=none- monitor only, no enforcement.p=quarantine- failing mail is sent to spam.p=reject- failing mail is refused outright. This is the goal, and what Gmail, Yahoo and Microsoft bulk-sender rules point toward.
The failures we find in audits
1. Jumping straight to p=reject
The single most damaging mistake. If any legitimate sender is not yet aligned - a marketing tool, a helpdesk, an old server - p=reject bounces that mail immediately. Always sit at p=none and read the reports first.
2. A record with no rua (flying blind)
Enforcing without a reporting address means you never see which senders are failing or being spoofed. Always include a rua= address and actually monitor it - that is the whole point of the monitoring stage.
3. The record on the wrong host
DMARC belongs at _dmarc.yourdomain.com, not the bare domain and not a random subdomain. Some panels auto-append your domain, so entering the full _dmarc.yourdomain.com can double it. Check what actually resolves.
4. Forgetting subdomains
By default a DMARC policy also applies to subdomains, but if you send from subdomains you may need a matching setup there too. If you never send from subdomains, an explicit sp=reject stops attackers using them to spoof you.
5. SPF/DKIM pass, DMARC still fails
This is alignment: DMARC needs the passing SPF or DKIM identity to match the visible From domain. Zoho Mail's own mail aligns, but a third-party tool sending "as" your domain with its own envelope or signature will not. Postbox DMARC Monitor shows exactly which sources are misaligned.
Verify it end to end
- Reports in plain language: point
ruaat Postbox DMARC Monitor and watch until every legitimate sender aligns. - One-email audit: send a message to Postbox Mailtester - SPF, DKIM and DMARC alignment in one view.
- Spoofability: can strangers still send as your domain? Run a Postbox Spoof Check.
Frequently asked questions
Where does the Zoho DMARC record go?
In your own DNS, not inside Zoho. Publish a TXT record at _dmarc.yourdomain.com. Zoho's Admin Console has a generator to help compose the value, but the record itself is added at your DNS host.
What DMARC policy should I start with?
Start at p=none with a rua reporting address. It changes nothing about how mail is treated; it just collects reports so you can confirm SPF and DKIM pass for every legitimate sender. Then move to p=quarantine, then p=reject.
Do I need SPF and DKIM before DMARC?
Yes. DMARC passes when a message aligns on SPF or DKIM, so set up the Zoho SPF and Zoho DKIM records first, both verified.
How do I read Zoho DMARC reports?
They arrive as XML from each provider - unreadable by hand. Point your rua at a monitor that parses them. Postbox DMARC Monitor turns the XML into a clear view of who sends as your domain and whether they pass.
Is it safe to jump straight to p=reject?
No. If any legitimate sender is not yet aligned, p=reject bounces their mail. Monitor at p=none first, fix every failing sender, then tighten.
Primary reference: Zoho Mail Admin Help - DMARC Policy. Also in Setup Guides: Zoho Mail SPF · Zoho Mail DKIM · DMARC enforcement (provider-agnostic) · Microsoft 365 DMARC.
Want your DMARC reports read for you, or the path to p=reject handled?