An email authentication policy published in DNS (as a TXT record at
_dmarc.<domain>) that tells receivers what to do with messages failing SPF and
DKIM alignment checks — none, quarantine or reject. It also enables aggregate and
forensic reporting so domain owners can see who is sending mail as them. DMARC
only works on top of SPF and/or DKIM; it does not authenticate anything itself.