p=reject — discard failing mail
p=reject asks receivers to refuse DMARC-failing mail outright, typically with an SMTP-level bounce, rather than delivering or quarantining it. This is the strongest available protection for a domain that wants full anti-spoofing coverage — it is only safe to set once you have confirmed, from real aggregate report data, that every legitimate sending source for the domain is passing SPF or DKIM with alignment.
Going to p=reject before every legitimate sender (billing systems, marketing platforms, forwarders) is accounted for will silently drop real mail — this is why this tool's approve-baseline/target-policy workflow exists, rather than editing the DNS record blind.
Note: RFC 9989 (DMARCbis) §3.2.9 defines "Enforcement" as any policy that isn't p=none — quarantine counts equally with reject as a genuine enforcement state, not just a waypoint on the way here. Reject remains the strongest option, but a domain that settles permanently on quarantine for a lighter-touch posture isn't doing DMARC "wrong."
- RFC 7489 §6.3