DMARC

DMARC generator and checker

DMARC tells mail servers what to do with mail that fails SPF or DKIM. Build a record or check an existing one.

Build a record

Where mail servers send aggregate reports.

Alignment

_dmarc.example.com.uaTXTv=DMARC1; p=none

Add it as a TXT record at _dmarc.yourdomain.

Three policy levels

p=none
Only observe and send reports; block nothing.
p=quarantine
Suspicious mail goes to spam.
p=reject
Suspicious mail is rejected outright.

The natural path: start with none, confirm from the reports that every legitimate sender passes, then move to quarantine, and later to reject.

Check a domain

Frequently asked

Which policy should I start with?

Always p=none. Blocking right away risks losing legitimate mail you forgot to add to SPF or DKIM.

What’s rua?

The address where mail servers send aggregate reports: who tried to send mail as your domain, and from where.