Cloudflare Security & compliance

No DMARC record (domain can be spoofed in email)

Part of the DNS & origin exposure check · fix arrives as a guide

What it is

The domain has no DMARC record.

Why it matters

Without DMARC, receiving servers have no instruction about what to do with mail that fails authentication, so anyone can send as your domain and it will often be delivered. This is the standard opening move in invoice and support fraud.

How to fix it

Publish a DMARC record at _dmarc starting with p=none and a reporting address, review the reports until your legitimate senders all pass, then move to p=quarantine and finally p=reject.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.