DMARC record generator
Build a valid DMARC record in seconds: choose a policy, reporting address, alignment and subdomain policy, then copy the TXT record to publish at _dmarc.
Build your DMARC record
Used to spot report addresses at another domain.
Start with none, read your reports, then tighten.
100 applies the policy to all failing mail and is left out of the record.
Comma separated. Daily XML reports arrive here.
Few receivers send these, and they can contain personal data.
Only used with a ruf address.
| Host | Type | Value |
|---|---|---|
_dmarc | TXT | v=DMARC1; p=noneFull name: _dmarc.yourdomain.com |
- Warning: No report address (rua). Receivers won’t send you aggregate reports, so you can’t see who sends mail as your domain or whether it passes.
- Note: p=none only monitors: nothing is blocked. It’s the right start, but plan to move to quarantine and reject.
A DMARC record is one TXT record at _dmarc.yourdomain.com. The minimum useful record is v=DMARC1; p=none; rua=mailto:you@yourdomain.com: it turns on daily reports without changing how your mail is delivered. Once the reports show every legitimate sender passing, change p to quarantine and then reject.
How to publish the record
- In your DNS host, add a TXT record. For the name, enter
_dmarc. Most DNS hosts add your domain automatically; if yours wants the full name, use_dmarc.yourdomain.com. - Paste the value exactly as generated. Quotes are optional at most hosts.
- If a DMARC record already exists, edit it instead of adding a second one. Two records mean receivers ignore DMARC entirely.
- Check it with the DMARC checker. New records usually show up within minutes.
What each tag does
| Tag | Values | Default if left out |
|---|---|---|
v | DMARC1 | Required, and must come first |
p | none, quarantine, reject | Required |
sp | none, quarantine, reject | Subdomains use p |
pct | 0 to 100 | 100 |
rua | mailto: addresses, comma separated | No aggregate reports |
ruf | mailto: addresses | No failure reports |
adkim, aspf | r (relaxed) or s (strict) | r |
fo | 0, 1, d, s | 0 |
The generator leaves out tags that equal their default, which keeps the record short and easy to read. The full definitions are in RFC 7489 section 6.3.
Which policy should you start with?
Start with p=none and a report address, even if you’re sure you know every sender. Most domains find at least one they forgot: a billing system, a CRM, a help desk or a website form. Jumping straight to reject bounces that mail. After two to four weeks of clean reports, move to quarantine, then reject. Moving from p=none to p=reject walks through the stages, and what DMARC is covers the basics.
Where should DMARC reports go?
Reports are XML files, sent daily by each mailbox provider, and a busy domain gets dozens a day. Sending them to a personal inbox works for a week. A report service parses them for you. If the address is at a different domain from yours, that domain has to publish an authorization record (yourdomain.com._report._dmarc.reportdomain) or receivers won’t send reports there. Report services publish it for their customers.
v=DMARC1; p=reject; rua=mailto:dmarc@example.comFrequently asked questions
Is v=DMARC1; p=none enough?
It’s valid, but without rua you get no reports, so you learn nothing and can’t safely move to enforcement. Always include a report address.
Do I need a separate DMARC record for each subdomain?
No. Subdomains without their own record use the parent domain’s record, with sp= if you set it. Publish a subdomain record only when it needs a different policy.
Should I use strict alignment?
Rarely. Strict alignment fails mail that’s signed or bounced through a subdomain of your domain, which many services do. Relaxed alignment still blocks other domains from passing as yours.
How long does a DMARC record take to work?
As soon as DNS serves it, usually minutes, up to the TTL of any record it replaced. The first aggregate reports arrive a day or two later, once receivers finish their daily reporting period.
Can I use more than one rua address?
Yes, separate them with commas: rua=mailto:a@example.com,mailto:b@example.com. Receivers send each report to every address. RFC 7489 only requires them to handle two, so don’t list more than that.