DMARC checker
Look up any domain’s DMARC record and see its policy, reporting addresses, alignment and subdomain rules, with a grade and the exact fixes. Free, no sign-up.
Look up a DMARC record
Enter a domain to fetch its DMARC record from public DNS. You’ll also get SPF and DKIM results, a score out of 100 and the fixes to make.
A DMARC record is a TXT record at _dmarc.yourdomain.com that starts with v=DMARC1. It tells receivers what to do with mail that fails authentication (p=none, quarantine or reject) and where to send reports (rua=). The checker reads it the way Gmail and Outlook do and flags anything that weakens it.
What the DMARC checker looks at
| Check | What we look for | Why it matters |
|---|---|---|
| Record exists | One TXT record at _dmarc starting with v=DMARC1 | No record or two records both mean no DMARC protection. |
| Policy (p=) | reject is best, quarantine is good, none only monitors | Only quarantine and reject stop spoofed mail. |
| Coverage (pct=, t=) | No pct below 100, and no t=y once you’re enforcing | Both soften the policy. RFC 9989 (2026) replaces pct with the t=y testing flag. |
| Subdomains (sp=) | Same as p, or stricter | Attackers pick subdomains when sp=none. |
| Reports (rua=) | At least one mailto: address | Without reports you can’t see who sends as you, so you can’t enforce safely. |
| Alignment (adkim, aspf) | Relaxed (r, the default) or strict (s) | Strict breaks mail from subdomains unless every sender signs exactly. |
Reading a DMARC record
v=DMARC1; p=reject; rua=mailto:reports@example.com; adkim=r; aspf=rv=DMARC1must come first. Without it receivers ignore the record.p=rejectasks receivers to refuse mail that fails DMARC.rua=mailto:…is where daily aggregate reports go. Reports to another domain need that domain’s permission record, which report services publish for you.adkim=r; aspf=ris relaxed alignment, the default. Mail fromnews.example.comstill aligns withexample.com.
Need a record? The DMARC record generator builds one. New to DMARC? Start with what DMARC is and how it works.
After the check
If you’re at p=none, the next step is to find every service that sends as your domain in your DMARC reports and make sure each one passes SPF or DKIM with alignment. Then move to quarantine and reject. Moving from p=none to p=reject walks through it.
Frequently asked questions
Where is the DMARC record published?
At the _dmarc subdomain of the domain in your From address, as a TXT record: for example _dmarc.example.com. Subdomains without their own record inherit the organizational domain’s record, using sp= if it’s set.
Why does the checker say my DMARC record wasn’t found?
Usually the record was added at the wrong name (_dmarc.example.com.example.com, when the DNS host appends the domain for you), it’s a new record that hasn’t propagated, or the value doesn’t start with v=DMARC1. Enter just _dmarc as the host at most DNS providers.
Can I have more than one DMARC record?
No. If a domain publishes two DMARC records, receivers ignore both and the domain has no DMARC policy at all. Merge them into one.
Is p=none bad?
p=none is the right place to start: it turns on reporting without affecting delivery. It doesn’t protect you from spoofing, though, so treat it as a step toward quarantine and reject rather than a destination.