What the checker looks at
DMARC lives in a TXT record at _dmarc.yourdomain.com. The checker fetches it, confirms it starts with v=DMARC1, and reviews each tag: the policy (p), the subdomain policy (sp), the reporting address (rua), the percentage (pct), and the alignment modes (adkim, aspf). If a subdomain has no record of its own, it falls back to the parent domain's policy, just as receivers do.
A safe path from none to reject
- Start with monitoring. Publish
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comand collect reports for two to four weeks. - Fix legitimate senders. The reports show every service sending as your domain. Make sure each one passes SPF or DKIM with your domain — check SPF with the SPF Checker.
- Quarantine. Move to
p=quarantine. You can phase it in withpct=25, then 50, then 100. - Reject. When reports stay clean, switch to
p=reject. Spoofed mail is now refused outright.
Common DMARC mistakes
- Publishing two records. Receivers ignore DMARC completely when they find more than one.
- Forgetting rua. Without reports you can't tell whether moving to quarantine will block your own invoices or newsletters.
- Writing rua without mailto:. The value must be a URI such as
mailto:dmarc@example.com, not a bare address. - Staying on p=none forever. It satisfies the Gmail and Yahoo minimum but gives you no protection against spoofing.
Frequently asked questions
DMARC is a DNS policy that tells receiving servers what to do with mail that fails SPF and DKIM alignment with your From domain, and where to send reports about it.
p=none only monitors: spoofed mail is still delivered. Use it for a few weeks while you read the rua reports, then move to quarantine and finally reject.
Since February 2024, Gmail and Yahoo require bulk senders (roughly 5,000+ messages a day to their users) to publish at least p=none. For every other domain it is strongly recommended because it stops spoofing.
Create a TXT record named _dmarc (for example _dmarc.example.com) at your DNS provider. A good starting value is v=DMARC1; p=none; rua=mailto:dmarc@example.com.
They set alignment mode. Relaxed (r, the default) accepts subdomains of your From domain; strict (s) requires an exact match.