Publishing a strict DMARC record protects your domain at Gmail, Outlook and other providers that enforce it. It does not, by itself, stop a forged message "from" your own domain arriving in your own mailbox: that depends on whether the receiving server, your server, checks DMARC on incoming mail. This guide explains the difference, what our shared hosting does with incoming mail, and how to enforce inbound checks on a mail server you run yourself.
DMARC is enforced by the receiving server. Our shared cPanel and DirectAdmin mail servers don't reject incoming mail for failing DMARC; they filter it with greylisting, blocklists and spam scoring, and you control your mailbox's spam filter. On your own server you can enforce inbound checks, either by refusing unauthenticated mail that uses your domain as the sender or by running a filter that verifies DMARC. Always test before you reject, because a wrong rule blocks genuine mail.
Publishing your own records is covered in Setting up DMARC. This article is about checking the mail that arrives.
1. Publishing DMARC versus enforcing it
The three records work together:
- SPF lists the servers allowed to send mail for your domain.
- DKIM signs each message with a key published in your DNS.
- DMARC requires SPF or DKIM to pass for the domain in the visible From address, and tells receivers what to do when neither does:
none,quarantineorreject.
Your DMARC record is only an instruction. Each receiving mail server decides whether to follow it. Large mailbox providers do. A small mail server only does if it has been set up to verify DMARC on incoming mail.
2. Why forged "internal" mail still gets through
A phishing message claiming to be from [email protected] and sent to [email protected] looks like internal mail. Three things let it through:
- The receiving server doesn't verify DMARC. Without that step, a
p=rejectrecord has no effect on mail your own server receives. - Envelope sender and header From differ. Servers check SPF against the hidden envelope sender. An attacker can use their own envelope sender, pass SPF for their domain, and still show your domain in the From line. Only DMARC ties the two together.
- Forwarding and relays change the sending server, so strict rules can also catch genuine forwarded mail. That is why every rule below needs testing.
3. What happens to incoming mail on Domain India shared hosting
We checked our shared mail servers on 24 September 2026. The Exim mail server on our cPanel and DirectAdmin servers is not built with DMARC verification, so incoming mail is not rejected because it fails the sender's DMARC policy. On our cPanel servers, incoming mail passes through:
- greylisting, which delays mail from unknown senders so many spam tools give up;
- Spamhaus and SpamCop blocklists, which refuse mail from known spam sources;
- SpamAssassin spam scoring, which you switch on and tune for your own account with Spam Filters.
The mail server's configuration is shared by every account on the server, so it can't be changed on shared hosting. What you can do:
- Tune your spam filter.In cPanel, open Email › Spam Filters to have likely spam moved to a separate folder and to adjust how strict the score is. On DirectAdmin, open E-mail Manager › SpamAssassin Setup; SPAM Filters in the same group blocks particular senders, words or domains.
- Add email filters for obvious fakes.A filter can flag or move messages whose subject or headers match a pattern you keep seeing.
- Publish strict records for your own domain.Once your genuine mail passes, move DMARC to
quarantineand thenreject, so large providers refuse forgeries in your name. DKIM is on by default for new cPanel accounts. - Train your team.A filter can't catch everything; see section 6.
4. Enforcing inbound checks on your own server
This section applies only to a mail server you run yourself, such as your own VPS or dedicated server. It does not apply to Domain India shared hosting.
First, check whether your Exim build can verify DMARC:
exim -bV | grep -i dmarcIf DMARC doesn't appear in the "Support for" line, Exim can't check DMARC itself, and you have two practical options.
Option A: refuse unauthenticated mail that uses your domain as the sender
If all of your genuine mail is sent by users who log in to your server, you can refuse messages that arrive from outside with one of your domains as the envelope sender. In Exim, add this to the RCPT ACL:
deny
!authenticated = *
!hosts = +relay_hosts
sender_domains = +local_domains
message = Unauthenticated mail using a local sender domain is refusedOn a cPanel server you manage, custom ACL lines go in WHM's Exim Configuration Manager, in the Advanced Editor. Limits of this rule:
- It checks the envelope sender only, so it stops the crudest forgeries, not a forged From line with an outside envelope.
- It blocks outside services that legitimately send as your domain, such as a newsletter tool, a CRM or Google Workspace, unless you add their servers to
relay_hostsor they use their own envelope domain. - It can break some forwarded mail.
Option B: verify DMARC with a mail filter
A content filter that understands DMARC checks the From domain against SPF and DKIM results and applies the sender's policy. Rspamd has a DMARC module that can add a header to mail failing a quarantine policy and reject mail failing a reject policy; SpamAssassin 4 can score DMARC results. Start in report-only or scoring mode, watch the results for a week or two, and only then reject.
A mistyped ACL or an over-strict filter can refuse every message your server receives. Make one change at a time, keep the previous configuration to roll back to, and test from an outside address after every change.
5. Testing and monitoring your own server
Start with a forged test message sent from a machine that isn't your mail server, using the swaks tool:
swaks --to [email protected] --from [email protected] --server mail.yourdomain.comWith option A in place, the server should refuse it at the RCPT stage. Then:
- Send genuine mail from a logged-in mailbox, your website and every outside service you use, and confirm each one still arrives.
- Read the logs. On a cPanel server, refused messages appear in
/var/log/exim_mainlog; search for your rule's message text. - Read your DMARC reports. The aggregate reports from your own record show who is sending as your domain and whether it passes.
- Keep the server updated, including Exim and the spam filter, and review the rules whenever you add or remove a sending service.
6. People are the last filter
- Check the sender's real address, not just the display name, and look for misspelt domains.
- Hover over links before clicking and compare the real destination.
- Confirm unusual requests for payments, passwords or bank changes by phone or in person, never by replying.
- Have one place to report suspicious mail inside your organisation.
7. Email security with Domain India
- Hosting email (cPanel, DirectAdmin, Webuzo): manage your SPF, DKIM and DMARC records in your panel's DNS editor if your domain uses our hosting nameservers, and tune your own spam filter as described above. For the DKIM selector and checks on DirectAdmin, see How to check and manage DKIM in DirectAdmin.
- Business Email: every incoming message is checked for SPF, DKIM and DMARC, and the results are recorded in its headers. Failures raise the spam score, and mail over the threshold is filed in the Junk folder rather than rejected, so you can still recover a genuine message.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
The price on the card is a live Domain India list price and excludes 18% GST. For the wider picture, see Email deliverability: SPF, DKIM, DMARC and BIMI.
Does a DMARC reject policy stop spoofed mail reaching my own mailbox?
Only if the server that receives the mail verifies DMARC. The policy is an instruction to receiving servers. Large providers such as Gmail follow it, but a mail server that is not set up to check DMARC on incoming mail will ignore it.
Does Domain India shared hosting reject incoming mail that fails DMARC?
No. The Exim mail server on Domain India's cPanel and DirectAdmin shared servers is not built with DMARC verification. Incoming mail on cPanel is filtered with greylisting and the Spamhaus and SpamCop blocklists, and you can switch on and tune SpamAssassin for your account with Spam Filters in cPanel.
Can I add a custom Exim rule on shared hosting?
No. The mail server's configuration is shared by every account on the server, so it can't be changed from a shared hosting account. You can adjust your own spam filter and email filters in your control panel.
How do I block mail that forges my domain on my own cPanel server?
Check whether your Exim build supports DMARC with exim -bV. If it doesn't, add an ACL rule in WHM's Exim Configuration Manager that refuses unauthenticated mail using one of your local domains as the envelope sender, or run a filter such as Rspamd that verifies DMARC. Test from an outside address before and after the change.
Why did a genuine message get blocked after I added a strict rule?
Usually because an outside service such as a newsletter tool, CRM or forwarding address sends mail with your domain as the sender without logging in to your server. Add that service's servers to your trusted relay hosts, or have it send with its own envelope domain and sign with your DKIM key.
Does Business Email check DMARC on incoming mail?
Yes. Domain India Business Email checks SPF, DKIM and DMARC on every incoming message. Failures raise the spam score, and messages over the threshold go to the Junk folder instead of being rejected.
Ready to lock down your domain's email? Publish your records with Setting up DMARC, look at Business Email, or open a support ticket if spoofed mail keeps reaching your inbox.
Every incoming message checked for SPF, DKIM and DMARC, with likely spam filed in the Junk folder.
See Business Email