DMARC Checker
Inspect any domain's DMARC record, understand every field, catch misconfigurations and get actionable email-security tips.
What is DMARC?
DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email authentication protocol designed to protect your domain from phishing and spoofing. It builds on SPF and DKIM.
- p=: Policy for main domain (none, quarantine, reject)
- sp=: Policy for subdomains
- rua=: Aggregate report receiver
- ruf=: Forensic report receiver
- adkim/aspf=: Alignment modes
DMARC Best Practices
- Use p=quarantine or p=reject for strong protection—p=none is informational only.
- Set up rua reports to monitor your DMARC effectiveness.
- Align SPF and DKIM for all sending domains.
- Regularly review DMARC reports and update policies as needed.
Common DMARC Misconfiguration Issues
- Missing DMARC record—domain is easily spoofed.
- Using p=none long-term—offers no enforcement.
- Incorrect rua/ruf mailto formatting.
- Subdomain policy not configured (sp missing).
Frequently Asked Questions
What does this DMARC checker do?
It looks up your domain's DMARC record (the TXT record at _dmarc.yourdomain.com), then explains each field — policy, alignment, reporting addresses — and flags weak or missing settings.
Is it free and private?
Yes. The lookup runs in your browser via public DNS-over-HTTPS. We don't store the domains you check.
What DMARC policy should I use?
p=reject gives the strongest protection. p=quarantine is a good intermediate step, and p=none only monitors — it offers no enforcement.
Why does my domain show no DMARC record?
It likely hasn't been set up yet. Add a TXT record at _dmarc.yourdomain.com starting with v=DMARC1 and a policy, after confirming SPF and DKIM are in place.
Learn more at dmarc.org · Built for admins & security pros.