SecureMyEmail logoSecureMyEmail
← All articles
Email security18 August 2026 · 5 min read

Boost Google Workspace Email Security: Set Up DMARC Quarantine

An Australian business owner securing Google Workspace email by setting up DMARC quarantine against phishing attacks.

▶ Watch the short explainer for this tip

Did you know that without proper email authentication, anyone can pretend to send emails from your business? It's called email spoofing, and it’s a big problem for Australian small and medium businesses (SMBs), leading to phishing attacks and scams. Today's tech tip shows you how to implement Domain-based Message Authentication, Reporting and Conformance (DMARC) on your Google Workspace domain and move it to quarantine. This critical step significantly boosts your email security, ensuring that only legitimate emails from your domain reach inboxes.

What is DMARC and how does it secure your emails?

Domain-based Message Authentication, Reporting and Conformance (DMARC) is an email authentication protocol that helps protect your domain from impersonation, phishing, and other email-based attacks. It tells receiving mail servers what to do with emails that fail both Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) checks, which are two other crucial email security standards. Implementing DMARC allows you to dictate policies, such as rejecting or quarantining emails that appear to come from your domain but aren't legitimate.

Why is DMARC Quarantine essential for your business?

Moving your DMARC policy to 'quarantine' is essential because it actively protects your customers and partners from receiving fraudulent emails that appear to originate from your business. This policy instructs email servers to place unauthenticated messages into the recipient's spam or junk folder, significantly reducing the success rate of phishing campaigns using your domain. It builds trust in your brand and protects your recipients from financial loss or malware.

What are the risks of not setting up DMARC Quarantine?

If you leave your DMARC policy at 'none' or don't set it up at all, your domain remains vulnerable to email spoofing and phishing attacks. This can lead to serious consequences: customers might fall victim to scams appearing to come from you, leading to reputational damage, customer churn, and potential legal or compliance issues, especially if sensitive data is involved. Ultimately, a lack of DMARC can cost your business money, cause downtime, expose data, impact insurance premiums, and even lead to notifiable data breach (NDB) incidents under Australian privacy law. If you’re not confident in your setup, you can book a complimentary 15-minute chat with Neil to discuss a security audit for your Google Workspace.

Step-by-step guide to setting up DMARC Quarantine

Implementing DMARC quarantine in your Google Workspace is a four-step process. Be sure to follow these instructions carefully and sequentially, as incorrect changes can disrupt your email service: 1. In admin.google.com go to Apps > Google Workspace > Gmail > Authenticate email, generate the DKIM key for your domain and publish the TXT record it gives you. 2. At your DNS provider confirm your SPF record ends with include:_spf.google.com ~all. 3. Add a TXT record named _dmarc.yourdomain.com.au with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com.au; pct=100 and leave it for two to four weeks. 4. Once the aggregate reports show only your legitimate senders passing, edit the record and change p=none to p=quarantine.

How to confirm DMARC is working and what to watch out for

To check it worked, send a message to an external mailbox and check the headers show spf=pass, dkim=pass and dmarc=pass. What might break is that marketing platforms, booking systems, and accounting software often send as your domain; you must align them before you move past p=none or their mail lands in junk. It's crucial to warn staff about potential changes to how some third-party emails are handled. If you need help with this alignment, book a complimentary 15-minute chat with Neil from Netlogyx IT to see how a security audit could benefit your Australian business.

Important Disclaimer

The steps provided are accurate at the time of publishing. However, email platform menus and defaults can change. If you are not confident in making these changes yourself, it's vital not to proceed, as incorrect alterations can disrupt your email service. SecureMyEmail by Netlogyx IT accepts no responsibility for loss or damage caused by changes made without our direct involvement.

Implementing DMARC quarantine for your Google Workspace is a non-negotiable step for modern email security. It protects your brand and recipients from email fraud, reinforcing trust and safeguarding against costly attacks.

Disclaimer: The steps are accurate at the time of publishing but email platform menus and defaults change; if the reader is not confident they should not change settings themselves because incorrect changes can disrupt email service; and SecureMyEmail accepts no responsibility for loss or damage caused by changes made without our direct involvement.

Frequently asked questions

What is DMARC and why do I need it for my Google Workspace?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication protocol that protects your domain from email spoofing and phishing. You need it for Google Workspace to ensure that only legitimate emails sent from your domain are delivered, enhancing your brand's trustworthiness and recipient safety.
What does setting DMARC to 'quarantine' mean?
Setting your DMARC policy to 'quarantine' means that if an email appears to come from your domain but fails authentication checks (SPF and DKIM), the receiving mail server should place it into the recipient's spam or junk folder. This is a crucial step beyond simply monitoring, as it actively reduces the threat of fraudulent emails.
How long does it take to implement DMARC quarantine?
Initially, you'll set DMARC to 'p=none' for two to four weeks to collect reports and ensure all legitimate senders are passing authentication. After this monitoring period and once you've confirmed your legitimate emails are authenticating correctly, you can then switch the policy to 'p=quarantine'.
Will DMARC quarantine affect my legitimate marketing emails or accounting software?
Yes, third-party services like marketing platforms, booking systems, or accounting software that send emails on behalf of your domain must be properly configured to pass SPF and DKIM checks. If they are not aligned before you switch from 'p=none' to 'p=quarantine', their emails could end up in recipients' junk folders. This is why the monitoring period with 'p=none' is essential.
Can I set up DMARC myself for my Australian small business?
While the steps are provided, setting up DMARC correctly requires careful attention to detail with your Google Workspace and DNS provider. Incorrect changes can disrupt your email service. If you're not confident, it's best to seek expert help or book a complimentary 15-minute chat with Neil at Netlogyx IT to discuss a security audit.

Sources

Every reference below was link-checked when this article was published.

  1. 1.Add a DMARC recordGoogle Workspace Admin Help
  2. 2.RFC 7489 — Domain-based Message Authentication, Reporting and ConformanceIETF

Want to know where your own tenant stands?

The audit answers these questions with a dated report on your actual settings — a few questions to start, under a minute.