Email authentication validator

🛡️ DMARC Checker

Inspect any domain's DMARC record, understand every field, catch misconfigurations and get actionable email-security tips.

Instant validation Field explanations Security recommendations

What is a DMARC record?

A DMARC (Domain-based Message Authentication, Reporting and Conformance) record is a DNS TXT record at _dmarc.yourdomain.com that tells receiving mail servers what to do with email that claims to be from your domain but fails authentication. DMARC is defined in RFC 7489.

A message passes DMARC when SPF or DKIM passes and the domain that passed matches ("aligns with") the From address the reader sees. That alignment is what stops attackers putting your domain in the From line.

v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; adkim=r; aspf=r

DMARC tags explained

TagWhat it doesValues (default)
vVersion. Must be first.DMARC1 (required)
pPolicy for mail that fails DMARC.none, quarantine, reject (required)
spPolicy for subdomains.Same values (inherits p)
pctPercentage of failing mail the policy applies to. Useful for gradual rollout.0-100 (100)
ruaWhere daily aggregate (XML) reports are sent.mailto: URIs (none)
rufWhere per-message failure reports are sent. Few receivers send them.mailto: URIs (none)
adkimDKIM alignment: relaxed allows subdomains, strict needs an exact match.r, s (r)
aspfSPF alignment, same idea.r, s (r)
foWhen to generate failure reports.0, 1, d, s (0)
riRequested seconds between aggregate reports.(86400 = daily)

How to roll out DMARC safely

  1. Set up SPF and DKIM for every service that sends as your domain (mail provider, newsletter tool, CRM, invoicing). Check SPF with our SPF Checker.
  2. Monitor with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Read the aggregate reports for 2-4 weeks and fix any legitimate sender that fails.
  3. Quarantine gradually: p=quarantine; pct=25, then 50, then 100 as reports stay clean.
  4. Reject: p=reject. Spoofed mail using your domain is now refused by receivers that enforce DMARC.
Gmail and Yahoo require bulk senders (around 5,000+ messages a day to their users) to publish DMARC, at minimum p=none, plus SPF, DKIM and alignment, since February 2024.

Common DMARC problems and how to fix them

ProblemWhat happensFix
No DMARC recordAnyone can put your domain in the From line; large mailbox providers may also throttle your mail.Start with v=DMARC1; p=none; rua=mailto:… at _dmarc.yourdomain.com.
Two DMARC recordsReceivers ignore DMARC for the domain.Keep exactly one TXT record starting with v=DMARC1.
p=none for monthsMonitoring only; spoofed mail is still delivered.Use the reports, then move to quarantine and reject.
rua without mailto:Reports are never sent.Write rua=mailto:dmarc@yourdomain.com.
Reports sent to another domainThe receiving domain must authorise it, or reports are dropped.The report domain publishes yourdomain.com._report._dmarc.reportdomain.com TXT v=DMARC1 (most report services do this for you).
Legit mail fails after enforcingA sender isn't in SPF or doesn't sign with your DKIM domain.Find it in the aggregate reports, then add it to SPF and enable DKIM signing for your domain.
sp weaker than pAttackers spoof anything.yourdomain.com instead.Remove sp (it inherits p) or set it equal.

Frequently Asked Questions

What does this DMARC checker do?

It looks up your domain's DMARC record (the TXT record at _dmarc.yourdomain.com), then explains each field - policy, alignment, reporting addresses - and flags weak or missing settings.

Is the DMARC checker free and private?

Yes. The lookup runs in your browser via public DNS-over-HTTPS. We don't store the domains you check.

What DMARC policy should I use?

p=reject gives the strongest protection. p=quarantine is a good intermediate step, and p=none only monitors - it offers no enforcement.

Why does my domain show no DMARC record?

It likely hasn't been set up yet. Add a TXT record at _dmarc.yourdomain.com starting with v=DMARC1 and a policy, after confirming SPF and DKIM are in place.

What is DMARC alignment?

DMARC passes only when SPF or DKIM passes for a domain that matches the visible From domain. Relaxed alignment (the default) accepts a subdomain match; strict alignment needs an exact match.

Do I need both SPF and DKIM for DMARC?

DMARC passes if either one passes and aligns, but set up both. DKIM survives email forwarding, while SPF usually breaks when a message is forwarded.

Learn more at dmarc.org · Last updated by Lazy Devs.