DMARC Record Checker

Check a domain's DMARC record, validate every tag, and find out whether your policy actually protects you from spoofing.

Bahasa Indonesia

Advertisement

What the checker looks at

DMARC lives in a TXT record at _dmarc.yourdomain.com. The checker fetches it, confirms it starts with v=DMARC1, and reviews each tag: the policy (p), the subdomain policy (sp), the reporting address (rua), the percentage (pct), and the alignment modes (adkim, aspf). If a subdomain has no record of its own, it falls back to the parent domain's policy, just as receivers do.

A safe path from none to reject

  1. Start with monitoring. Publish v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and collect reports for two to four weeks.
  2. Fix legitimate senders. The reports show every service sending as your domain. Make sure each one passes SPF or DKIM with your domain — check SPF with the SPF Checker.
  3. Quarantine. Move to p=quarantine. You can phase it in with pct=25, then 50, then 100.
  4. Reject. When reports stay clean, switch to p=reject. Spoofed mail is now refused outright.

Common DMARC mistakes

  • Publishing two records. Receivers ignore DMARC completely when they find more than one.
  • Forgetting rua. Without reports you can't tell whether moving to quarantine will block your own invoices or newsletters.
  • Writing rua without mailto:. The value must be a URI such as mailto:dmarc@example.com, not a bare address.
  • Staying on p=none forever. It satisfies the Gmail and Yahoo minimum but gives you no protection against spoofing.

Frequently asked questions

DMARC is a DNS policy that tells receiving servers what to do with mail that fails SPF and DKIM alignment with your From domain, and where to send reports about it.

p=none only monitors: spoofed mail is still delivered. Use it for a few weeks while you read the rua reports, then move to quarantine and finally reject.

Since February 2024, Gmail and Yahoo require bulk senders (roughly 5,000+ messages a day to their users) to publish at least p=none. For every other domain it is strongly recommended because it stops spoofing.

Create a TXT record named _dmarc (for example _dmarc.example.com) at your DNS provider. A good starting value is v=DMARC1; p=none; rua=mailto:dmarc@example.com.

They set alignment mode. Relaxed (r, the default) accepts subdomains of your From domain; strict (s) requires an exact match.
Ad
Advertisement
Ad
Advertisement