What should receivers do with mail that fails?
Where should reports go?
Daily XML summaries of who sent mail as your domain and whether it passed. Separate multiple addresses with commas.
Per-message failure samples. Few receivers send these and they can contain recipient data, so most domains leave this blank.
Your DMARC record
v=DMARC1; p=quarantine
No rua= address set. Without an aggregate-report mailbox you get no visibility into who's sending — or spoofing — as your domain. Add one before enforcing.
How to publish this
Add oneTXT record at the host _dmarc (so the full name is _dmarc.yourdomain.com) with the value above. A domain may have only one DMARC record. If you send the reports to a domain you don't own, that domain needs a matching authorisation record — most in-house setups report to their own domain, which needs nothing extra.Free tool — nothing you type leaves your browser. Want to check an existing record too? Run the DNS Health Checker.
§ WHY IT MATTERS
SPF and DKIM check the mail. DMARC enforces the answer.
1
TXT record at _dmarc — the whole policy on a single line
3
policies to graduate through: none → quarantine → reject
0
logins, installs, or data sent anywhere — it all runs in your browser
§ HOW IT WORKS
Four choices, one enforced policy.
Choose a policy
Start at p=none to monitor, then graduate to quarantine and reject. We flag the trap of staying on none forever.
Add report addresses
Point rua= at a mailbox you control so you actually see who's sending — and spoofing — as your domain.
Tune the details
Optionally set subdomain policy, SPF/DKIM alignment, and a rollout percentage for a gradual, safe ramp-up.
Copy & publish
Copy the finished record and paste it as a single TXT record at the _dmarc host on your domain.
§ THE PRIMER
What DMARC is really doing
SPF and DKIM each answer a narrow question — did this server have permission to send, and was the message signed and unaltered. DMARC ties them to your visible From address and adds the two things they lack: an instruction for what to do when a message fails, and a stream of reports so you can see it happening. That's what turns authentication from a quiet background check into actual anti-spoofing protection.
The mistake almost everyone makes is treating p=none as the finish line. It blocks nothing — it only monitors. It exists so you can collect a few weeks of aggregate reports, confirm every legitimate source of your mail passes alignment, and then move up to quarantine and finally reject. Skip the reports and jump straight to reject and you risk silently dropping real mail; stay on none forever and spoofers sail right through.
This generator builds the record in the right tag order and nudges you toward a mailbox for your reports and a real enforcement policy — the two things that make DMARC worth publishing. Choose your settings, copy the line, and add it as a single TXT record at _dmarc.
DMARC is the third leg of the stool. Get SPF and DKIM solid first, publish DMARC on top, and verify your recipient list before each send — so a locked-down, trusted domain isn't paired with dead addresses and spam traps.
§ FAQ
DMARC record FAQ
What DMARC does, how to roll it out safely, and where the reports go.
Still have questions? Contact us§ PROTECT YOUR DELIVERABILITY
Trusted domain. Clean list.
Lock down spoofing with DMARC, then verify your recipients before you send. Free plan includes 50 verifications a month — no card required.
Start for free