Glossary

What Is DMARC?

The DNS policy that tells receiving servers what to do with mail that fails authentication, and why cold senders need one.

Get your free API key →Free to start. No credit card. 1,000 records to spend whenever you like.

DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email standard that lets a domain owner publish a policy telling receivers what to do with mail that fails SPF and DKIM alignment, and asks them to send back reports.

The standard is defined in RFC 7489 (September 2026). The policy lives in one DNS TXT record at _dmarc.yourdomain.com. DMARC builds on SPF and DKIM. It adds two things they lack: a policy and a report.

Why it matters for outbound

Mailbox providers now expect it. Google's sender guidelines list SPF, DKIM and DMARC as requirements for bulk senders and say unauthenticated mail may be marked as spam or rejected (Google, September 2026). Sending cold email from a domain with no DMARC record puts your volume at risk first.

DMARC also protects the domain you sell from. A policy of quarantine or reject stops others from spoofing it. The reports show which tools send mail as you, so you can find a forgotten sender before it hurts your reputation.

A message passes DMARC only when SPF or DKIM passes and the passing domain matches the visible From address. That match is domain alignment.

Example

A sales team sends cold email from acme.com. This is the record they publish. The values are placeholders.

code
_dmarc.acme.com  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@acme.com; pct=100"

p=none means monitor only. Receivers deliver as usual and send daily aggregate reports to the rua address. After a few weeks of clean reports, the team moves to p=quarantine, then to p=reject.

Jumping straight to reject is the common mistake. If a legitimate tool is not yet aligned, its mail is dropped.

Check every sending tool first: your mail provider, your sequencer and any billing or support system that sends as acme.com. Each one needs SPF or DKIM aligned to the From domain before you tighten the policy.

In LeadOcean data

LeadOcean has no DMARC field, filter or endpoint. DMARC is a property of your own sending domain, not of the people or companies in the dataset. You set it in your DNS.

What LeadOcean does cover is the recipient address. Every person record carries email_status, and /v1/people/search accepts an emailStatus filter, so you can mail only verified addresses (openapi.json, September 2026). Passing DMARC does not rescue a list full of bounces.

For rollout steps, see the DMARC setup guide. For how it affects cold email, read DMARC for outbound and DMARC, SPF and DKIM explained. Pricing is on /pricing.

Send from an aligned domain to addresses that are already verified

Free to start. No credit card. 1,000 records to spend whenever you like.

Get your free API key →