DMARC checker

Look up any domain’s DMARC record and see its policy, reporting addresses, alignment and subdomain rules, with a grade and the exact fixes. Free, no sign-up.

Look up a DMARC record

Enter a domain to fetch its DMARC record from public DNS. You’ll also get SPF and DKIM results, a score out of 100 and the fixes to make.

A DMARC record is a TXT record at _dmarc.yourdomain.com that starts with v=DMARC1. It tells receivers what to do with mail that fails authentication (p=none, quarantine or reject) and where to send reports (rua=). The checker reads it the way Gmail and Outlook do and flags anything that weakens it.

What the DMARC checker looks at

CheckWhat we look forWhy it matters
Record existsOne TXT record at _dmarc starting with v=DMARC1No record or two records both mean no DMARC protection.
Policy (p=)reject is best, quarantine is good, none only monitorsOnly quarantine and reject stop spoofed mail.
Coverage (pct=, t=)No pct below 100, and no t=y once you’re enforcingBoth soften the policy. RFC 9989 (2026) replaces pct with the t=y testing flag.
Subdomains (sp=)Same as p, or stricterAttackers pick subdomains when sp=none.
Reports (rua=)At least one mailto: addressWithout reports you can’t see who sends as you, so you can’t enforce safely.
Alignment (adkim, aspf)Relaxed (r, the default) or strict (s)Strict breaks mail from subdomains unless every sender signs exactly.

Reading a DMARC record

A typical record at enforcement
v=DMARC1; p=reject; rua=mailto:reports@example.com; adkim=r; aspf=r
  • v=DMARC1 must come first. Without it receivers ignore the record.
  • p=reject asks receivers to refuse mail that fails DMARC.
  • rua=mailto:… is where daily aggregate reports go. Reports to another domain need that domain’s permission record, which report services publish for you.
  • adkim=r; aspf=r is relaxed alignment, the default. Mail from news.example.com still aligns with example.com.

Need a record? The DMARC record generator builds one. New to DMARC? Start with what DMARC is and how it works.

After the check

If you’re at p=none, the next step is to find every service that sends as your domain in your DMARC reports and make sure each one passes SPF or DKIM with alignment. Then move to quarantine and reject. Moving from p=none to p=reject walks through it.

Frequently asked questions

Where is the DMARC record published?

At the _dmarc subdomain of the domain in your From address, as a TXT record: for example _dmarc.example.com. Subdomains without their own record inherit the organizational domain’s record, using sp= if it’s set.

Why does the checker say my DMARC record wasn’t found?

Usually the record was added at the wrong name (_dmarc.example.com.example.com, when the DNS host appends the domain for you), it’s a new record that hasn’t propagated, or the value doesn’t start with v=DMARC1. Enter just _dmarc as the host at most DNS providers.

Can I have more than one DMARC record?

No. If a domain publishes two DMARC records, receivers ignore both and the domain has no DMARC policy at all. Merge them into one.

Is p=none bad?

p=none is the right place to start: it turns on reporting without affecting delivery. It doesn’t protect you from spoofing, though, so treat it as a step toward quarantine and reject rather than a destination.