DMARC Record Checker

Look up and explain a domain's DMARC policy, reporting addresses and alignment settings.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving mail servers what to do with messages that fail SPF and DKIM checks — deliver, quarantine or reject them — and where to send reports.

Example DMARC record

_dmarc.example.com  TXT  "v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; pct=100"

Policies

p=Effect
noneMonitor only — failing mail is still delivered
quarantineFailing mail goes to spam
rejectFailing mail is refused — the strongest protection

Rolling out DMARC safely

  1. Publish p=none with a rua address and read the reports for a few weeks.
  2. Make sure every legitimate sender passes SPF or DKIM with alignment.
  3. Move to p=quarantine, then p=reject.

If you check a subdomain without its own record, the tool shows the policy inherited from the main domain.

Frequently asked questions

Is p=none enough?

It meets the Gmail and Yahoo requirement to have DMARC, but it does not stop spoofing. Aim for quarantine or reject.

What are rua reports?

Daily aggregate XML reports from receivers listing which servers sent mail as your domain and whether it passed.

What does alignment mean?

The domain in the visible From address must match the domain verified by SPF or DKIM. Relaxed (r) allows subdomains; strict (s) requires an exact match.