DMARC Analyzer

Why approving the baseline is a deliberate action

← All help articles · Domain policy concepts

A baseline that gets set automatically defeats its own purpose — if the tool just copied whatever DNS says into the baseline the moment it's observed, an attacker's tampered record would become "approved" the instant it's read, and drift detection would never fire. Approving is refused entirely until a published policy has actually been observed at least once (so there's something real to approve), and it's always a deliberate, audit-logged admin click.