DMARC Record Generator

Build a valid DMARC record in a few clicks, then roll it out safely from monitoring to full protection.

Bahasa Indonesia

Separate multiple addresses with commas.

Your DMARC record

Type: TXT

Host/Name: _dmarc


                    
Advertisement

Rolling out DMARC without blocking your own mail

  1. Week 0: publish p=none with a rua address. Nothing changes for delivery yet.
  2. Weeks 1–4: read the aggregate reports. Every service that sends as your domain shows up there. Make each one pass SPF or DKIM with your domain — the SPF Checker and DKIM Checker help here.
  3. Then: switch to p=quarantine. If you're cautious, use pct=25 first and raise it.
  4. Finally: move to p=reject once reports show only failures you don't recognize.

What each tag does

  • p — what receivers do with mail that fails DMARC.
  • sp — the same for subdomains; defaults to p.
  • rua — where daily aggregate reports are sent.
  • pct — the share of failing mail the policy applies to.
  • adkim / aspf — relaxed alignment accepts subdomains of your From domain; strict requires an exact match.

Frequently asked questions

Start with p=none and a rua address. Read the reports for a few weeks, fix any legitimate service that fails, then move to quarantine and finally reject.

Create a TXT record with the host _dmarc (the full name is _dmarc.yourdomain.com) and paste the generated value. A domain must have only one DMARC record.

Yes, but the receiving domain must publish an authorization record (yourdomain.com._report._dmarc.otherdomain.com). Most DMARC reporting services set this up for you.

Usually not. Few large mailbox providers send them, and they can contain personal data. Aggregate reports (rua) are what you need.
Ad
Advertisement
Ad
Advertisement