DMARC pct less than 100 with p=reject falls to quarantine
Discover why DMARC pct < 100 with p=reject leads to quarantine. Learn how to fix it and improve deliverability with accurate email verification.
Why does DMARC pct < 100 with p=reject cause messages to be quarantined?
You send emails from your domain, and you’ve set DMARC to reject unauthenticated messages. But some still end up in quarantine or spam. Why?
It’s not the tool. It’s the policy. When you set p=reject but pct=90, you’re telling receivers: “I only enforce this 90% of the time.” That small gap—10%—is enough for some servers to treat your messages as suspicious. And many modern platforms see that inconsistency as a sign of weak sender reputation.
DMARC’s pct value isn’t just a number—it’s a signal. Receiving servers use it to decide how strictly to apply your policy. A pct below 100 means enforcement is incomplete, and that creates ambiguity. Even if your email is legitimate, the lack of full consistency can trigger automatic quarantine.
Key takeaways
- Setting
pct=90withp=rejectmeans 10% of messages are not subject to rejection, creating enforcement gaps. - Receiving servers interpret partial enforcement as a signal of poor sender reputation, increasing the risk of quarantine.
- Only full enforcement (
pct=100) withp=rejectreliably signals trust to modern email platforms.
What happens when DMARC pct < 100 and p=reject is combined?
If your DMARC policy sets p=reject but the pct value is less than 100, only a fraction of your domain’s messages are subject to rejection. This creates a gap: up to 10% of emails from your domain can slip through untested, even if they’re forged. Attackers can exploit this to spoof your brand with valid-looking messages, while receiving servers treat your legitimate emails as suspicious due to the inconsistency in your policy. This undermines your security posture and harms deliverability.
Why the inconsistency matters
DMARC is designed to enforce email authentication, but only when policies are applied consistently. If p=reject is set but pct is, say, 90, then 10% of messages — including potentially fake ones — aren’t subjected to rejection. That’s a window attackers can use to send phishing or scam emails that appear to come from your domain.
Receiving servers monitor these policies closely. When they see a mismatch—like a strict reject policy with partial enforcement—they apply cautious filtering. Your valid messages may land in spam or be delayed, even if they pass SPF and DKIM. It’s not punishment for you; it’s a response to signal noise from inconsistent policy enforcement.
How to fix it
Set pct=100 when using p=reject. This ensures every message from your domain is either fully authenticated or blocked. It removes ambiguity and gives receiving servers confidence in your domain’s integrity. The DMARC RFCs (like RFC 7483) emphasize that p policies should be applied at scale to be effective.
Check your DMARC reports regularly. Tools like DMARC Analyzer or MXToolbox can show you how well your policy is enforced. If you see significant traffic with no authentication, your policy may be misconfigured or only partially active.
Before sending mass campaigns, verify your sending domains and addresses. Use MailTester’s bulk verification to catch invalid, disposable, or non-existent addresses that could weaken your deliverability. It’s especially useful for auditing sender lists where some emails may have been added incorrectly or by mistake.
How does a low DMARC pct affect inbox placement?
If your DMARC policy has a pct value less than 100, even with valid SPF and DKIM, email receivers treat your domain as less trustworthy. This incomplete enforcement signals poor configuration, leading providers like Google and Microsoft to apply extra scrutiny. The result? Higher bounce rates, increased spam filtering, and lower inbox placement—even for legitimate messages.
Why low pct undermines sender reputation
You might have SPF and DKIM set up correctly, but if your DMARC policy uses pct=90 or lower, receivers see that you're not fully enforcing authentication on all your emails. This ambiguity reduces trust. Email providers don’t assume you’re doing it right—instead, they apply caution, especially when seeing repeated messages from senders with incomplete policies.
Google's postmaster tools and Microsoft’s spam reports both document that domains with low pct values are more likely to be flagged for suspicious behavior. Even a single unauthenticated message in a high-volume send can trigger filters. This isn't about a single failure—it's about consistent signals of inconsistent governance.
What happens to deliverability
When ISPs detect a low pct, they often route your emails to quarantine instead of the inbox. You’ll see increases in hard bounces and soft bounces, especially from Gmail and Outlook. Some providers now use this behavior as a signal in their spam scoring models. That’s why even well-written, highly engaged email content can end up in spam folders.
It’s not just theoretical. The DMARC specification (RFC 7483) states that pct is a percentage of messages to which the policy applies. A value less than 100 means a portion of your email isn’t covered—leaving the door open for abuse or misconfiguration. If you're using p=quarantine as your policy, and pct is under 100, you're effectively asking receivers to treat your messages as unverified by default.
Let’s say you’re sending to a large list. If only 90% of your messages pass authentication, that 10% of unverified traffic can undermine your domain reputation. It’s like sending 10 unmarked packages into a high-security building—eventually, the whole sender gets extra screening.
Use MailTester’s Inbox Placement tool to see how your DMARC setup affects delivery across real providers. You can also verify the authenticity of your entire list with bulk verification or integrate directly via the real-time verification API. If you're tracking performance, our pricing lets you start with 100 free checks—credits never expire.
Is there a recommended DMARC configuration for high deliverability?
You should use either pct=100 with p=reject or p=quarantine to enforce strict alignment and maximize inbox placement. Configurations with pct<100 and p=reject can cause legitimate emails to be blocked unpredictably, especially if you’re not actively monitoring reports. The standard approach is to start with p=none, then move gradually to quarantine and finally reject once you’ve confirmed all sending sources are covered.
Best Practice: Start Low, Scale Up
- Begin with
p=noneandpct=100to collect DMARC reports without affecting delivery. - Use RFC 7483 as a reference for how DMARC policies work in practice—misalignment is a common cause of quarantine.
- Once you’ve validated all sending sources (internal teams, marketing platforms, third-party vendors), transition to
p=quarantinewithpct=100. - Only after consistent success and full visibility should you enable
p=rejectwithpct=100. - Avoid
pct=90or lower in production—these can result in unpredictable delivery failures, especially when your email volume is high or includes dynamic sources.
Monitor Reports, Not Just Policy
If you're running a p=reject policy with pct<100, any email from an unaligned source or missing signature will fail—no matter how legitimate. This can be especially risky when using platforms like SendGrid, HubSpot, or Klaviyo unless you’re certain they’re properly aligned.
Use DMARC reporting to identify false negatives. For example, if you see a spike in “policy=quarantine” results for a known sender, investigate if SPF or DKIM is misconfigured.
Let’s be clear: DMARC is not a deliverability booster by itself—it’s a control mechanism. Its value only emerges when paired with accurate authentication and active monitoring.
Consider running test batches through inbox placement testing to validate that your final configuration doesn’t trigger filters at major providers like Gmail or Outlook.
Use bulk verification to ensure your email list is clean and includes only valid, deliverable addresses before pushing messages through a strict DMARC policy.
The goal isn’t just to enforce rules. It’s to prevent spoofing while ensuring every real email reaches the inbox.
How can you verify if your DMARC policy is properly enforced?
You can verify enforcement by testing real message delivery through your configured SPF, DKIM, and DMARC policies using tools that simulate inbox placement, inspect email headers for authentication results, and analyze DMARC aggregate reports. Only by sending actual messages—preferably through your authorized services like Mailchimp, SendGrid, or HubSpot—and tracing their journey can you confirm whether your p=reject policy is actually being applied or falling to quarantine due to incomplete alignment.
Test delivery with real-world validation tools
Don’t rely on hypotheticals. Use email verification tools that send real messages through your domain’s infrastructure and report back on how they were treated. These tools check if an email lands in the inbox or is quarantined based on DMARC, SPF, and DKIM results. The DMARC specification defines how receivers interpret p=reject but only if all authentication checks pass. If your sending sources aren’t properly aligned, you’ll see quarantined deliveries despite a strict policy.
Check logs and reports for consistent enforcement
Monitor your DMARC aggregate reports (RUA) to see if authentication failures are consistently flagged. A high number of failures from legitimate sending systems—especially those tied to third-party platforms—can indicate missing entries in SPF records or misaligned DKIM signatures. If your policy is set to p=reject but you still see delivery to inboxes without rejection, it likely means the policy isn’t fully enforced due to alignment gaps. Use inbox placement testing to see how real email clients react to messages from your domain.
Ensure every sending IP and service is explicitly listed in your SPF record and that DKIM is properly configured for each sender. Even if your domain’s overall DMARC policy is set to p=reject, inconsistent or missing configurations in your sending ecosystem will result in messages being quarantined or accepted—undermining your policy's effectiveness. MailTester’s bulk verification and API allow you to test thousands of addresses and validate whether messages from your domain are auth-qualified end-to-end. You can’t assume security is enforced—you must verify it at scale.
What are the risks of using p=reject with pct < 100?
You risk blocking legitimate messages when using p=reject with pct<100, because any email from an unlisted source—like a new sender, third-party vendor, or mobile user—gets rejected. This forces all non-compliant messages into quarantine or rejection, even if they’re valid. As a result, your deliverability drops, sender trust erodes, and you’re more likely to be flagged as suspicious. Let’s break down why.
Legitimate emails get caught in the crossfire
If you set p=reject but pct is below 100, any email that doesn’t match your listed sources is treated as invalid. That includes messages from your support team using a new alias, a partner sharing a campaign, or an automated system from a previously unused IP. These messages, though genuine, will be quarantined or bounced—often without warning. It’s like locking the front door but leaving the back open, then blaming the mail carrier for not delivering a letter.
Spam filters and reputation systems take note
When a policy like p=reject with pct<100 is applied, it signals inconsistency. Spam filters see this as a sign of poor domain hygiene. A 2022 report from the Anti-Phishing Working Group noted that inconsistent DMARC policies correlate strongly with higher spam classification rates. Email receivers don’t know whether you’re protecting your domain or misconfiguring it. Either way, they treat you as unreliable. APWG research shows that domains with mismatched authentication policies are more likely to be flagged by major filters.
Over time, this reduces inbox placement. Even valid messages from your core systems start landing in spam or being throttled. Recipients complain more. Your sender reputation declines. And once that happens, it’s hard to rebuild.
That’s why many senders start with p=quarantine and monitor traffic before enforcing p=reject. It gives visibility and time to validate all sources. It also prevents collateral damage.
You don’t need to wait for a failed send to fix your DMARC policy. Use tools that test your domain’s full authentication stack—including SPF, DKIM, and DMARC—before rolling out strict enforcement. MailTester’s inbox placement tester lets you simulate real recipient behavior across mail servers. It shows you how your messages are being treated today, not what you think they should be.
How can email verification help fix DMARC-related deliverability issues?
You can improve DMARC effectiveness by cleaning your email list with tools like MailTester: removing invalid, malformed, or unverifiable addresses reduces bounces and spam trap hits, both of which harm sender reputation. A healthier sender reputation strengthens DMARC enforcement—especially when p=reject is in place—because inbox providers trust consistent, high-quality sending behavior. By catching issues early with real-time verification, you stop deliverability problems before they trigger quarantine or rejection.
Preventing spam traps and bounce fatigue
If your list includes old, dormant, or disposable addresses, you risk hitting spam traps. These are inactive addresses set up to catch spammers. Every bounce or hard failure from such an address erodes your sender reputation, making your DMARC policy (even with p=reject) less effective over time. MailTester’s verification API and bulk list checks identify these dead zones before you send, letting you remove them. This reduces bounce rates and the chance of false positives in spam filtering. RFC 7483 notes that sender reputation is a key factor in email filtering decisions, so maintaining a clean list is essential.
Validating sender reputation through verified lists
DMARC only works if the receiving side trusts the sending domain. High bounce rates and poor engagement signal poor list hygiene, leading providers to treat your messages as suspicious—especially when p=reject is enforced. By using MailTester’s bulk verification, you ensure that only valid, deliverable addresses remain in your list. This consistency builds sender reputation over time. A reputation score that stays high means your DMARC policy (especially p=reject or p=quarantine) is more likely to be applied as intended, rather than being ignored or bypassed. Appriss Intelligence reports that deliverability rates above 90% are common among high-reputation senders—something verified lists help achieve.
Once your list is clean, test it under real conditions. MailTester’s inbox placement service simulates what happens when your message hits an actual inbox—using real domains, client types, and filtering rules. This shows whether your DMARC policy (p=reject) successfully lands messages in the inbox, or gets rerouted to quarantine. Use the inbox placement test to validate your full sender stack before sending to large audiences.
What’s the impact of sending from unauthenticated sources on DMARC?
If your domain’s DMARC policy has a pct value below 100% and uses p=reject, any email sent from unauthenticated sources—like a misconfigured third-party tool or a compromised account—can escape strict enforcement if it falls outside the percentage threshold. This means even one misaligned send can bypass rejection and still be delivered, weakening your domain’s overall authentication posture. Over time, repeated unauthenticated sends degrade sender reputation, and high failure rates in DMARC reports often trigger quarantine or blocklist actions from receiving providers.
Why partial enforcement undermines DMARC’s purpose
DMARC was designed to give domains full control over email authentication. But when pct is set to, say, 90%, the remaining 10% of messages—especially those from unknown or unverified sources—are not subject to p=reject. If those sends fall outside the coverage, the policy effectively doesn’t enforce alignment, even if SPF or DKIM fails. This creates a blind spot where attackers or compromised systems can send malicious or misleading emails without consequence.
Let’s say your marketing platform accidentally sends from a non-authorized IP that doesn’t pass SPF or DKIM. If that send falls into the 10% not covered by pct, it still gets through, and the lack of authentication erodes trust. Major inbox providers like Google and Microsoft watch for consistent authentication failures across a domain. Repeated failures, even if partially covered, signal poor control and can lead to filtering or blocking.
How DMARC reporting reflects real-world risks
DMARC aggregate reports show how many emails fail SPF, DKIM, or alignment checks. If those failure rates climb—especially from unknown sources—receiving providers interpret this as a sign that your domain is not well-managed. According to industry data from the Messaging, Malware, and Mobile Anti-Abuse Working Group (M3AAWG), domains with high failure rates in DMARC reports are significantly more likely to be flagged for spam filtering or placed on blocklists.
Even when p=reject is in place, the pct setting determines how much of your outbound email is actually protected. A pct of 100% ensures every message is checked and rejected if authentication fails. Anything less leaves room for exploitation. Regularly checking your DMARC reports and testing inbox placement helps catch misconfigurations early. You can validate your domain’s alignment and test deliverability with tools like MailTester’s Inbox Placement Tester, which checks how your messages land in real consumer inboxes across major providers.
How do role accounts and disposable domains affect DMARC and deliverability?
Role accounts (like info@, sales@) and disposable email domains often lack proper authentication, increasing the risk of failed DMARC checks. When your DMARC policy is set to p=reject but pct is below 100%, messages to these addresses may be quarantined instead of rejected—reducing deliverability and harming sender reputation. You’re essentially letting risky sends slip through, which harms long-term inbox placement.
Role accounts: the hidden risk in your list
Role accounts are common in marketing lists but rarely have proper email authentication set up. They often lack SPF, DKIM, or DMARC alignment, making them vulnerable to being flagged as suspicious. If your DMARC policy is p=reject with pct under 100%, these addresses will trigger quarantine instead of outright rejection. This means your message might still be delivered, but it lands in the spam folder, which still counts as a failed deliverability signal.
According to the RFC 7483, DMARC is designed to protect against spoofing—but it only works reliably when all components are properly implemented. Sending to unauthenticated role accounts undermines that protection. You can use tools like MailTester’s bulk verification to identify and clean these addresses before sending.
Disposable domains: false signals and reputation drains
Disposable email domains (like temp-mail.org or 10minutemail.com) are created for short-term use. They frequently lack SPF and DKIM records, or worse—may have poorly configured ones that appear to pass but are actually invalid. Sending to them can create false authentication signals, especially when DMARC pct is below 100%. This skews your sender reputation metrics over time.
These domains are commonly used for spam sign-ups or phishing, which means any mail to them is often flagged by receiving servers. Even if your message doesn't get bounced, you may see higher spam complaints or engagement penalties. The risk compounds when you’re sending to a mix of role accounts and disposable domains under a strict DMARC p=reject policy with low pct.
By validating your list with real-time checks, you can avoid sending to these risk-prone addresses. MailTester’s API integrates with your workflows to validate addresses on the fly, reducing bounce rates and protecting your sender reputation. Testing inbox placement with MailTester’s inbox tester can also show you how well your messages land—even when DMARC policies are partially enforced.
Checklist: Ensuring DMARC enforcement works correctly
If your DMARC policy is set to p=reject with pct=100, but still sees emails land in quarantine instead of being rejected, the issue is likely incomplete authentication alignment across all sending sources — including third-party platforms. You must verify SPF and DKIM are properly configured for every sender, and monitor aggregate reports to catch unauthenticated traffic. Poor list hygiene and undetected invalid addresses can also cause enforcement gaps. Test real delivery to inboxes and validate your list with a dependable email verifier.
Core setup and alignment
- Set your DMARC record to
p=rejectwithpct=100to enforce rejection of unauthenticated messages. This is the only way to fully stop spoofing. - Verify every sending source — including your ESPs, marketing tools, and transactional systems — is listed in both SPF and properly signed with DKIM.
- Use RFC 7483 (the DMARC standard) to ensure your policy syntax is correct, and regularly validate using tools like DMARCian's checker.
- Monitor aggregate DMARC reports from receivers like Google and Microsoft to spot unauthorized senders or misconfigured systems.
List quality and delivery validation
- Keep sender lists clean: remove role accounts (e.g. admin@, info@), disposable domains, and known invalid addresses. These often fail authentication and harm sender reputation.
- Test inbox placement using real email delivery tools. If messages land in spam or quarantine despite correct DMARC, the issue is likely reputation, content, or IP signal — not policy.
- Use a trusted email verifier like MailTester’s bulk verification to audit your list accuracy and catch dead or risky addresses before sending.
- Integrate verification into your workflow via the MailTester API to automate list cleanups and avoid repeated failures.
- Review your sending behavior with inbox placement testing to validate that policies like
p=rejectare actually being honored by receivers. - Regularly recheck your SPF, DKIM, and DMARC setup, especially after onboarding new tools or modifying email routes.
Even with a strict p=reject policy, enforcement fails if your list contains unauthenticated senders or invalid addresses. The policy only applies to messages that come from your domain — not to malformed or outdated email entries.In conclusion: DMARC pct < 100 with p=reject is a deliverability risk
When DMARC pct is less than 100% with p=reject, authentication enforcement is incomplete. This means legitimate messages may still be quarantined or rejected — even if they pass SPF and DKIM.
Partial enforcement signals weakness. Recipients’ email systems see inconsistent policy enforcement and may distrust your domain. A pct of 100% ensures all messages are evaluated under the same standard, regardless of source.
Fixing the issue requires three steps:
- Full enforcement with pct=100 in your DMARC record.
- Clean, accurate email lists that don’t include invalid or inactive addresses.
- Real-world testing to confirm inbox placement and avoid unexpected delivery failures.
Sources
- Only 22.9% of top domains enforce DMARC with p=quarantine or p=reject, while 29.2% remain in monitoring-only p=none mode that blocks nothing. — EasyDMARC 2026 DMARC Adoption & Enforcement Report (2026)
- Since May 5, 2025, Microsoft Outlook requires SPF, DKIM, and DMARC from domains sending 5,000+ emails per day, rejecting non-compliant mail outright at the SMTP level with error 550 5.7.515. — Microsoft Outlook requirements (via MailOver bulk-sender requirements guide) (2025)
Keep reading
- Email authentication: SPF, DKIM, DMARC, BIMI and MTA-STS (complete guide)
- DKIM Key Rotation Without Downtime Using Two Selectors
- DMARC pct=100 default — Do I Need to Write It?
- 163.com 554 IP is rejected DT:SPM vs DT:SPF Explained
- How Much Does a BIMI VMC Cost per Year DigiCert Entrust 2026
Ready to put this into practice? MailTester verifies emails with 98.9% accuracy — start with 100 free verifications.
Frequently asked questions
What does DMARC pct < 100 mean in practice?
It means only a percentage of messages are subject to the stated policy, leaving gaps in enforcement.
Can p=reject work with pct < 100?
Yes—but it creates inconsistent enforcement, leading to quarantined or rejected messages.
Why does DMARC with pct < 100 send to quarantine?
Receiving servers interpret incomplete enforcement as a sign of misconfiguration or risk.
How does email verification improve DMARC effectiveness?
It removes invalid, disposable, and role-based addresses that harm sender reputation.
What should my DMARC policy be for best delivery?
Use p=reject with pct=100, ensure all senders are authenticated, and monitor reports.
Does MailTester check DMARC compliance?
No—it doesn’t test DMARC directly, but it helps maintain sender reputation through accurate list hygiene.
Why do some emails get quarantined even with p=reject?
Because of incomplete DMARC enforcement or improper SPF/DKIM alignment.
How often should I review my DMARC reports?
Monthly, to identify new unauthenticated senders and adjust configurations accordingly.
Can a high bounce rate affect DMARC?
Yes—bounces from invalid addresses can reduce reputation, making DMARC enforcement less effective.
Do disposable email addresses violate DMARC?
Not directly—but they often come from unverified sources, increasing spam risk and lowering deliverability.
Is it safe to use p=quarantine before p=reject?
Yes—p=quarantine is a testing phase that allows monitoring before enforcing rejection.
How does list hygiene impact DMARC success?
Clean lists reduce bounce and spam complaints, improving sender reputation and policy effectiveness.