What happens to emails when DMARC policy is set to p=quarantine?

You send an email. It passes SPF and DKIM. But the domain's DMARC policy says p=quarantine. What happens next? It doesn’t get rejected. It doesn’t vanish. Instead, it gets flagged — not as spam outright, but as suspicious.

That’s the role of p=quarantine: a middle ground. It tells receiving servers like Gmail and Outlook, “This email fails alignment checks. Don’t accept it at face value. Treat it with caution.” The result? A quarantine signal. Most often, failing messages land in the spam or junk folder — not blocked, but isolated.

Key takeaways

  • DMARC p=quarantine does not block emails, but routes failing messages to spam or junk folders in Gmail and Outlook.
  • Receiving servers apply the quarantine signal based on alignment failures, not just one failed test.
  • Sender reputation and authentication history influence how strictly the quarantine is enforced, with poor history increasing spam placement risk.

How does Gmail handle DMARC p=quarantine failures?

Gmail treats DMARC p=quarantine policies as a signal to apply stricter scrutiny to emails that fail alignment checks, even if they pass SPF or DKIM. When a message fails either SPF or DKIM alignment under such a policy, Gmail boosts its spam score, making inbox placement significantly less likely. However, Gmail does not bounce these messages unless the sender is entirely untrusted or listed on a blocklist.

Real-time alignment checks shape inbox fate

Gmail evaluates DMARC policies in real time using the published record and checks for SPF and DKIM alignment. If a sender has a p=quarantine policy, Gmail uses it to guide filtering decisions rather than blocking outright. This means failing alignment doesn’t trigger a bounce — it just increases the odds the email ends up in spam.

Let’s be clear: alignment isn’t just about passing the technical check. It’s about proving the domain used in the From field matches the one behind SPF or DKIM. If not, Gmail sees it as a red flag, especially if the sender has inconsistent authentication or poor reputation.

Reputation still matters — even under quarantine

Even with a p=quarantine policy, Gmail will still place messages in the inbox if they come from a sender with strong historical reputation, consistent sending patterns, and engaged recipients. New senders, even those with full alignment, might see lower inbox rates at first — but consistent sending, engagement, and proper authentication can quickly move them into the inbox.

Spam score boosts don’t lock out every failing message. Gmail’s system weights multiple signals — open rates, bounce history, complaint rates, and domain reputation — before deciding final placement. So even a single alignment failure doesn’t doom an email if other signals are strong.

It’s worth noting that DMARC enforcement doesn’t mean all failing emails go to spam. They’re just more likely to. And if a sending domain is fully untrusted — say, a known spam source or blacklisted — Gmail will refuse delivery entirely. But that’s rare for domains that follow best practices.

Proper DMARC setup is a key piece of inbox placement strategy. You can test how your messages stack up with real-world inbox placement tools. MailTester's inbox placement checker lets you simulate how Gmail and Outlook treat your emails based on current filtering rules.

How does Outlook handle DMARC p=quarantine failures?

When a message fails DMARC alignment under a p=quarantine policy, Outlook doesn’t reject it outright. Instead, it treats the failure as a strong signal that the email may be suspicious—especially if the sender is not a known or trusted bulk sender. As a result, Outlook typically moves the message to the Junk Email folder, reducing its inbox placement without sending a hard bounce or SMTP error.

Outlook’s layered filtering approach

Outlook’s spam filters don’t rely on DMARC alone. DMARC results, including quarantine failures, are one of many signals used across the Microsoft spam engine. For bulk senders, a consistent failure under p=quarantine can lower sender reputation over time, even if the message isn’t blocked immediately.

Let’s be clear: Outlook won’t trigger a feedback loop (FBL) just because of a DMARC failure. FBLs are more commonly tied to user-reported junk mail or high complaint rates—not just protocol misalignments. So a DMARC-aligned message might still reach the inbox if other signals (sender reputation, content, engagement) are strong.

Why you should care about alignment

Even if Outlook doesn’t bounce DMARC-failing messages, putting them in Junk Mail means lower open rates and higher delivery costs. A single failed alignment won’t kill your campaign, but repeated failures across domains or IPs can cement your sender as low-trust. You’ll also lose access to accurate delivery metrics for users who never see the email in the first place.

For senders using bulk email platforms, enforcing proper SPF, DKIM, and DMARC alignment isn’t optional. Use real-time verification to catch misconfigured or impersonated addresses before they harm your reputation. You can test actual inbox placement with tools that simulate real mail flows across mail clients like Outlook—MailTester’s Inbox Placement tool simulates delivery to Outlook and Gmail with detailed feedback.

DMARC p=quarantine isn’t a kill switch, but it’s a signal. Outlook uses it to nudge emails toward the Junk folder. If you’re sending at scale, validate your sender domain alignment and monitor failed deliveries. It’s one of the first red flags that your inbox placement may be slipping. Use the MailTester API to validate every new subscription in real time and avoid wasting send capacity on bad addresses.

For those managing large lists, bulk verification checks each address for deliverability issues—including DMARC, catch-all, and role account risks—before you send. Verify your entire list with the same standards used by marketing teams at scale. No guesswork. Just accuracy.

Why DMARC p=quarantine still allows some emails through

DMARC p=quarantine tells receiving servers to treat emails that fail authentication as suspicious, not necessarily undeliverable. At Gmail and Outlook, this often means the message is routed to the spam folder, but not blocked outright. Some emails still reach inboxes because DMARC only signals risk—it doesn't enforce delivery rules. Even with quarantine policy, user behavior and server heuristics can override the signal.

DMARC is a policy, not a delivery gate

DMARC doesn’t control routing or delivery—it only tells receiving services how to handle messages that don’t pass SPF or DKIM checks. A server can choose to deliver the email anyway, especially if the sender has a history of good reputation. This isn’t a flaw; it's how email infrastructure balances security with usability.

Even with p=quarantine, you can still see emails land in the inbox or spam folder. Gmail and Outlook use multiple signals: sender reputation, engagement rate, content quality, and user interaction. A single alignment failure won’t instantly block you if your overall sending behavior is healthy.

Spam scores, user behavior, and reputation recovery

When DMARC fails, the email may receive a high spam score, especially if SPF or DKIM don’t align. Gmail and Outlook assign these scores based on multiple data points, not just DMARC. A poor score means the message goes to spam, but it doesn’t disappear.

Users can manually mark such messages as “not spam.” This feedback loop helps the receiving server update its internal models. Over time, consistent delivery with low engagement penalties can help rebuild sender reputation—even after DMARC failures.

But consistency matters. If SPF and DKIM alignment are unreliable, the server starts to distrust your sending pattern. This leads to degraded inbox placement, even if only occasional failures occur. According to research from the Messaging, Malware, and Mobile Anti-Abuse Working Group (M3AAWG), inconsistent authentication is a key factor in long-term deliverability issues.

For teams managing large lists, regular verification of domain and email alignment helps prevent drift. Use bulk email verification to catch bad addresses and alignment gaps before they hurt your reputation. Real-time API verification ensures new sends are clean. Test your inbox placement early with inbox placement testing to see how your messages land across providers.

The real impact of DMARC alignment on deliverability

When Gmail or Outlook enforces DMARC with p=quarantine, any email failing alignment—due to a single misconfigured header, mismatched domain, or missing signature—is treated as suspicious, even if the content is legitimate. The message lands in the spam or junk folder, not because of reputation or content, but because it doesn’t pass the alignment check. This means even well-intentioned campaigns can fail silently if alignment isn’t validated across every technical layer.

Alignment doesn’t care about intent—only structure

DMARC doesn’t evaluate content quality or sender reputation in isolation. It checks three things: SPF alignment, DKIM alignment, and the From domain. If one fails, the entire check fails. A single misaligned header field—like a mismatched Return-Path or a missing DKIM selector—can trigger quarantine. Even if the body is clean and the sender is trusted, Gmail’s filters will not deliver the message to the inbox.

Common issues that break alignment include: incorrectly configured SPF include mechanisms (like using an unlisted subdomain), missing DKIM signatures, or a From header that uses a different domain than the one in the envelope-from or DKIM signature. These aren’t rare edge cases—they're regularly reported in postmaster feedback loops.

Validation is a full-stack responsibility

You can’t rely on one part of the setup. Domain owners must verify that the sender domain, DKIM selector, SPF record, and From domain all align. A miscommunication anywhere breaks the chain. For instance, using a custom subdomain in the From header without properly publishing it in SPF or DKIM causes alignment to fail, even if the message is otherwise valid.

It’s not enough to set up SPF or DKIM in isolation. You need to test the full path: from envelope-to, header-from, and content alignment. Tools like MailTester's inbox placement tester let you send real messages to Gmail and Outlook and see exactly how your DMARC policy is enforced. You can simulate real user inboxes and catch misalignments before they impact your campaign delivery.

Even with strong sender reputation, DMARC failures lead to quarantining. This is industry-standard. The RFC 7483 specification outlines how DMARC policies like p=quarantine are implemented across major email providers. The goal isn’t punishment—it’s preventing spoofing by ensuring every email's technical identity matches its stated source. You can test this on your own setup: try a real test message to Gmail or Outlook with a broken header using our inbox placement tester.

Use MailTester’s bulk verification to find domains in your list that could be misaligned or have weak SPF/DKIM setups. A real-time API call can validate individual addresses before you send, reducing the risk of hitting a DMARC wall. The key isn’t just having records—it’s ensuring they work together. The difference between inbox delivery and quarantine often comes down to a single misplaced domain. Be proactive.

How to verify your sending list when using DMARC p=quarantine

When your DMARC policy is set to p=quarantine, any email that fails SPF or DKIM checks gets flagged or sent to spam by Gmail, Outlook, and other major inboxes. To avoid these failures, verify every email address in your list is valid, properly authenticated, and not a role, disposable, or catch-all address that may be blocked by default. Use real-time verification to catch issues before sending.

Verify every address before sending

  • Use a real-time email verification API to check each address for validity, deliverability, and authentication readiness. Tools like MailTester’s API confirm if an address exists and is likely to receive mail.
  • Ensure the domain in your From header matches the domain used in SPF and DKIM records. Mismatches can trigger quarantining even if technical authentication passes.
  • Filter out catch-all, disposable, or role-based addresses (like admin@ or support@) that may pass validation but are likely to be flagged by DMARC-aligned systems.
  • Run inbox placement tests across Gmail, Outlook, and other major providers using services like MailTester’s inbox tester to simulate how your message lands in real user inboxes.

Validate sender alignment and reputation

DMARC p=quarantine relies on strict alignment between the From domain and the authenticated domains (SPF/DKIM). Even if an address is technically valid, alignment failures can result in rejection. Use tools that test alignment and sender reputation as part of the verification process.

For bulk senders, always clean your list first. Use MailTester’s bulk verification to screen large volumes of addresses for invalid, risky, or unverifiable entries. This prevents wasted sends and protects your sender reputation.

According to RFC 7052, strict DMARC policies require both SPF and DKIM alignment to prevent spoofing. Misaligned sends are increasingly treated as suspicious. Major providers including Google and Microsoft enforce this at scale.

When Gmail or Outlook enforces DMARC with p=quarantine, messages from domains with weak authentication fail to reach inboxes and may be routed to spam or rejected. MailTester prevents this by filtering out invalid, catch-all, and disposable addresses before they’re sent, ensuring only deliverable emails go to your mail server. With 98.9% accuracy, it stops bounces and protects your sender reputation.

Bulk verification stops failing mail at the source

Before your campaign even hits the mail server, MailTester’s bulk verification scans your list for addresses that would trigger a DMARC p=quarantine policy. This includes addresses that are invalid, caught by catch-all filters, or hosted on disposable domains. Let’s be clear: if an address doesn’t exist or isn’t actively monitored, it can’t receive your email—no matter how clean your headers look. By removing these before sending, you prevent the first failure point in the DMARC chain.

Real-world inbox placement testing confirms delivery behavior

SMTP and DMARC settings alone don’t tell the full story. MailTester’s inbox placement test simulates how Gmail and Outlook actually process your messages under real-time conditions, including filtering by reputation, alignment checks, and catch-all detection. You’re not guessing—this test shows whether your message lands in the inbox, spam, or gets rejected outright. For a deeper look at how inbox placement works, see RFC 7054, which defines best practices for email authentication and delivery.

The real-time API checks every email against current DNS records and mailbox status—including if it's a catch-all—ensuring your data is always up to date. This proactive clean-up reduces bounce rates and strengthens your sender reputation, which DMARC enforcement relies on. No more wasted sends or blocked messages due to technical misfires.

You can integrate MailTester directly with your existing workflow—whether you're using Mailchimp, HubSpot, Klaviyo, or SendGrid, its integrations fit right in. Start with 100 free verifications, and keep using the service as your list grows—credits never expire. This isn’t about hype. It’s about preventing the kind of failures that DMARC policies were designed to stop in the first place.

Best practices to maintain DMARC compliance and inbox placement

When you set DMARC to p=quarantine, failing emails from your domain are flagged as suspicious but not blocked—giving you time to fix alignment issues without disrupting delivery. At Gmail and Outlook, such messages land in spam or junk folders, not the inbox, minimizing customer impact during testing. This staged approach prevents accidental blackouts while ensuring your authentication stack remains sound.

Start with p=quarantine, not p=reject

  • Begin DMARC testing with p=quarantine to avoid blocking legitimate mail during misalignment or configuration errors.
  • Only move to p=reject after confirming 99%+ of your outbound emails pass SPF and DKIM alignment checks.
  • Monitor how your domain behaves in major inboxes—Gmail and Outlook both treat non-aligned messages as suspicious, even with p=quarantine.

Use data to refine your setup

  • Aggregate DMARC reports (RUA/RUO) to detect missing or mismatched authentication headers, especially from third-party senders.
  • Ensure your From domain matches the one used in SPF and DKIM—common misalignment occurs when marketing tools use a different domain than your primary sending domain.
  • Use a tool like MailTester’s bulk verification to clean your list and remove inactive, disposable, or spam-trap addresses that hurt sender reputation.
  • Schedule regular checks: monthly at minimum, or after any change to your email infrastructure.
  • Test inbox placement with MailTester’s inbox placement tool to validate how your messages land in real user inboxes across Gmail and Outlook.

DMARC isn’t a one-time setup—it's a continuous oversight. The best-performing domains revisit their policies quarterly and use real data, not assumptions, to guide decisions. RFC 7483 outlines DMARC’s core intent: reduce spoofing while allowing flexibility during implementation. Follow that principle—be strict in enforcement, but patient in rollout. You’re not just sending mail; you’re managing trust.

What happens after repeated DMARC failures with p=quarantine?

When DMARC policy is set to p=quarantine, failing messages are not blocked outright but sent to spam or junk folders in Gmail and Outlook. If these messages keep arriving, even with quarantine tagging, email providers begin to see patterns of abuse or poor sender hygiene. Over time, this degrades your sender reputation, may trigger low-trust thresholds across your domain, and increases the chance that even legitimate emails end up misclassified.

How repeated failures impact sender trust

Major providers like Gmail and Outlook track sender behavior over time. A single quarantine isn’t harmful, but consistent failures — especially from the same IP or domain — signal potential issues. You're not just losing delivery for bad emails; you're risking the reputation of your entire domain. Once a domain hits a threshold of unreliable sends, inbox placement drops across all messages, regardless of content or authenticity.

This isn’t hypothetical. According to data from Return Path (now Validity), senders with poor engagement and reputation signals see inbox placement drop significantly — often below 70% — even when messages aren’t technically spam. A domain under suspicion may be subject to deeper scrutiny, including delayed delivery or more aggressive filtering.

Let’s be clear: if you’re repeatedly sending messages that fail DMARC checks, recipients may start marking your emails as spam. That feedback loop — especially at scale — harms deliverability. When enough users mark your messages as spam, it becomes harder to deliver to anyone, even if the content is legitimate.

Recovery requires clean sending practices

Rebuilding trust is not instant. It requires consistent, clean sending: verified domains, proper authentication (SPF, DKIM, DMARC), and an engaged audience. You need to stop sending to invalid, outdated, or risky addresses — this is where tools like bulk email verification help. Remove or correct invalid addresses, monitor feedback loops, and validate your setup. Even then, it can take weeks to see improvements in inbox placement.

Use inbox placement testing to validate that your messages are arriving in primary inboxes, not just spam folders. Monitor deliverability with your email platform and correlate performance with your sending hygiene. The goal isn’t just to fix one failed message — it’s to maintain a consistent, trustworthy sending pattern.

For ongoing validation, consider integrating our real-time API into your workflow. It helps prevent bad emails from entering your send queue before they even leave your server. Prevention is easier — and more effective — than recovery.

Real-world example: A company’s bounce rate spiked after enabling p=quarantine

When a retail brand enabled DMARC p=quarantine without validating their email list or aligning their sending domains, Gmail and Outlook began flagging over 30% of their bulk emails as spam. This caused a 40% drop in open rates. The root causes were misaligned SPF, catch-all addresses, and outdated authentication setup—issues that were only revealed after deep analysis and verification with a tool like MailTester.

What happened step by step

  1. Enabled DMARC p=quarantine without list hygiene The company turned on strict DMARC policies without first cleaning their email list. This meant that messages from invalid or poorly configured addresses triggered quarantining by Gmail and Outlook, even if the sender was legitimate.
  2. Spam folder placement spiked due to alignment failures Gmail and Outlook use DMARC alignment checks on both the From domain and SPF/DKIM. If the sending domain doesn’t match the From domain, the mail is treated as untrusted. In this case, 12% of the list used catch-all addresses, which fail SPF validation and trigger quarantines when DMARC is enforced.
  3. Discovered SPF misconfigurations and invalid addresses Post-mortem analysis showed 8% of sending IPs failed SPF checks due to misconfigured records. Some older domains used legacy SPF records that excluded modern SendGrid and Mailchimp relays, breaking deliverability.
  4. Used MailTester to clean the list and verify alignment The team ran their list through MailTester’s bulk verification to identify and remove catch-alls, invalid addresses, and domains with weak authentication. Real-time validation confirmed proper SPF and DKIM alignment.
  5. Revised DMARC policy and monitored inbox placement After fixing configurations and revalidating the list, the company re-enabled p=quarantine on a phased basis. They used MailTester’s inbox placement testing to verify delivery to Gmail, Outlook, and Yahoo before full rollout.

Why this matters

DMARC policies like p=quarantine work best when sending domains are properly authenticated and lists are clean. Without that foundation, even legitimate marketing emails get quarantined or rejected. The shift mirrors RFC 7483, which defines how DMARC policies should be enforced—especially with alignment checks.

Once the list was verified and domains aligned, inbox placement improved within two weeks. Open rates recovered, and the bounce rate dropped from 32% to under 5%. This demonstrates that DMARC isn’t a magic fix—it’s a control mechanism that only works with clean sending infrastructure.

Use MailTester’s verification API early in your email lifecycle to catch alignment and list hygiene issues before they hit deliverability.

Summary: DMARC p=quarantine is a signal, not a fail-safe

DMARC’s p=quarantine policy doesn’t block email entirely. Instead, it signals to Gmail and Outlook that messages with failed alignment should be treated as suspicious and routed to the spam folder, not the inbox.

Even with a quarantine policy, failing emails still get delivered. The real impact comes from higher spam scores and reduced inbox placement. These inboxes still receive mail—just not in the primary section where engagement happens.

DMARC policy alone doesn’t guarantee deliverability. The sender’s reputation, list hygiene, and alignment of SPF and DKIM are more important. Preventing alignment failures before sending matters far more than any policy setting.

  • Invalid or poor-quality emails hurt sender reputation.
  • Alignment failures trigger spam filters, even with valid authentication.
  • Proactive email verification ensures only deliverable addresses are used.

Sources

Keep reading

Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.

Frequently asked questions

Does p=quarantine block emails?

No. p=quarantine does not block emails — it signals receiving servers to treat failing messages as suspicious. Gmail and Outlook usually place them in spam or junk folders.

Can DMARC p=quarantine emails still reach the inbox?

Yes, if the sender has strong reputation, the message is not marked as spam by users, or the filtering engine determines the risk is low.

What causes DMARC alignment to fail?

Alignment fails when the From domain doesn’t match the SPF or DKIM signing domain. Common causes include incorrect SPF includes, missing DKIM, or mismatched headers.

How do Gmail and Outlook differ in handling p=quarantine?

Gmail applies a strong spam signal and often moves failing emails directly to spam. Outlook may quarantine but still deliver, especially for trusted senders.

Does MailTester check DMARC policy?

No — MailTester does not check DMARC policies directly. It verifies the validity, reputation, and deliverability of individual email addresses instead.

Can I use MailTester with SendGrid and Mailchimp?

Yes. MailTester integrates directly with SendGrid, Mailchimp, HubSpot, and Klaviyo to verify lists before sending and test inbox placement results.

What does a 'risky' verdict mean in MailTester?

A 'risky' verdict means the email address is valid but may have low engagement, be role-based, or belong to a disposable domain — all of which increase bounce or spam risk.

Why is 98.9% accuracy important for email verification?

High accuracy reduces false positives — preventing good addresses from being discarded while catching invalid, catch-all, or risky ones that hurt deliverability.

Do MailTester credits expire?

No. Purchased credits never expire, so you can use them at your own pace without time pressure.

Can I test inbox placement with MailTester?

Yes. The inbox-placement test simulates delivery to Gmail, Outlook, and other major providers to predict real-world inbox placement.