DMARC
DMARC generator and checker
DMARC tells mail servers what to do with mail that fails SPF or DKIM. Build a record or check an existing one.
Build a record
Where mail servers send aggregate reports.
Alignment
_dmarc.example.com.uaTXTv=DMARC1; p=noneAdd it as a TXT record at _dmarc.yourdomain.
Three policy levels
p=none- Only observe and send reports; block nothing.
p=quarantine- Suspicious mail goes to spam.
p=reject- Suspicious mail is rejected outright.
The natural path: start with none, confirm from the reports that every legitimate sender passes, then move to quarantine, and later to reject.
Check a domain
Frequently asked
Which policy should I start with?
Always p=none. Blocking right away risks losing legitimate mail you forgot to add to SPF or DKIM.
What’s rua?
The address where mail servers send aggregate reports: who tried to send mail as your domain, and from where.