DMARC Analyzer

sp= — subdomain policy

← All help articles · DMARC fundamentals

sp= overrides p= for mail claiming to be from any subdomain of the published domain (e.g. mail.example.com, newsletter.example.com) that doesn't itself publish its own DMARC record. Without sp=, subdomains inherit p=.

Leaving sp= unset while an attacker spoofs a plausible-looking subdomain that never sends real mail is exactly the gap this tool's R11 recommendation watches for — publishing sp=reject on a domain that has no legitimate subdomain traffic is usually safe and closes off a common spoofing vector.

Under DMARCbis (RFC 9989), a new np= tag sets a policy specifically for subdomains that don't exist in DNS at all — distinct from sp=, which covers subdomains that exist but publish no record of their own. It's optional and defaults to whatever sp=/p= already resolve to; no current domain in this tool needs to set it to stay correctly configured.

References