Defaults.Exposed

Defaults.Exposed › Setup › DMARC

How to set up DMARC on Beget

Add a DMARC record in Beget to tell mail providers what to do with email that fails your checks.

Why this matters to your business

DMARC ties SPF and DKIM together and adds the missing instruction: what should a receiving mail provider do when an email claiming to be from you fails the checks? Without DMARC, each provider guesses. With it, you decide — and you can ask them to send you reports showing who is sending mail in your name.

In plain terms: DMARC is what actually stops criminals from spoofing your domain to scam your customers or staff. It’s the policy on top of the locks SPF and DKIM provide — free, and well worth the few minutes.

Set up SPF and DKIM first

DMARC works by checking the results of SPF and DKIM. If you haven’t added those yet, do them first — a DMARC policy with nothing underneath it has nothing to enforce.

Confirm Beget runs your DNS

This record only works if Beget is answering DNS for your domain — that is, your domain’s nameservers point to Beget’s nameservers (the default for domains registered or hosted at Beget). If they point to another company, add the DMARC record at whichever provider runs your DNS instead.

Step-by-step on Beget

DMARC lives on the host _dmarc.yourdomain.com, which in Beget is a subzone you create first. Labels below are the Russian originals with English equivalents; confirm exact wording in your console.

  1. Sign in to the Beget control panel and open the DNS section.
  2. Select your domain in the list at the top.
  3. Click «Добавить подзону» (Add subzone) and create a subzone named exactly: _dmarc Enter only _dmarc — Beget appends your domain automatically.
  4. Select the new _dmarc subzone, then click «Открыть режим редактирования» (Open editing mode).
  5. In the «Быстрое добавление» (Quick add) block, set the record type to TXT.
  6. Paste a monitoring-only policy into the data field: v=DMARC1; p=none; rua=mailto:[email protected] Replace the address with a mailbox you actually read. This asks providers to email you summary reports without changing how any mail is treated yet.
  7. Save the record.

Choosing your policy (the p= part)

Run p=none for a few weeks, read the reports to confirm all your legitimate mail passes, then move up to quarantine and finally reject. Jumping straight to reject before you’ve checked the reports risks blocking your own genuine email.

Beget quirks people get wrong

Verify it worked

Once saved and propagated, run the free check on this site. It will tell you in plain language whether your DMARC record is in place and what policy you’ve set.

See the full fix guide →

Done? Check your domain free to confirm it worked — and see your full grade across all 34 checks.