DMARC Checker

Look up a domain’s DMARC record, validate every tag and see exactly what to fix to protect the domain from spoofing and phishing.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard defined in RFC 7489. It builds on SPF and DKIM and lets a domain owner tell receiving mail servers what to do with messages that claim to come from the domain but fail authentication.

A DMARC record is a TXT record published at _dmarc.yourdomain.com. It contains a policy (none, quarantine or reject), the addresses where receivers should send reports, and optional settings for alignment and subdomains. Since 2024 Google and Yahoo require a DMARC record from everyone who sends bulk email, so a missing record now directly hurts deliverability.

How to use this DMARC checker

  • Enter a domain name, an email address or a URL — we extract the domain automatically.
  • We query _dmarc.<domain> in public DNS. If a subdomain has no record, we check the organizational domain whose policy applies to it.
  • Every tag is parsed and validated against RFC 7489: policy values, pct range, alignment modes, report addresses and failure options.
  • You get a clear status, a list of errors and recommendations, and a table that explains each tag in plain language.

DMARC record example

A typical record for a domain that is ready for full enforcement looks like this:

v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s; pct=100

It rejects every message that fails both SPF and DKIM alignment, applies the same policy to subdomains and sends daily aggregate reports to the given mailbox.

DMARC policies explained

  • p=none — monitoring only. Failing mail is delivered normally, but you receive reports. Start here to discover all legitimate senders.
  • p=quarantine — failing mail is delivered to the spam or junk folder. A safe intermediate step.
  • p=reject — failing mail is refused during the SMTP transaction. This is the goal: it fully protects your domain from direct spoofing.

Move gradually: publish p=none with a rua address, review the reports for a few weeks, fix SPF and DKIM for every legitimate service, then switch to quarantine and finally to reject. The pct tag lets you apply the policy to a percentage of mail while you roll out.

Common DMARC errors

  • Multiple records — publishing two DMARC TXT records at the same name makes receivers ignore both.
  • v=DMARC1 not first — the version tag must be the very first tag, otherwise the record is discarded.
  • Invalid report address — rua and ruf values must be URIs such as mailto:reports@example.com, not bare email addresses.
  • External reports not authorized — when reports go to another domain, that domain must publish an authorization record, or receivers will not send them.
  • Staying on p=none forever — a monitoring policy provides visibility but no protection against spoofing.

DMARC, SPF and DKIM work together

DMARC passes when a message passes SPF or DKIM and the authenticated domain aligns with the domain in the visible From address. That is why a correct DMARC setup always starts with valid SPF and DKIM records. Use our SPF checker and DKIM checker to verify them, then send a test message to a temporary TempBox address to see the real authentication results in the headers.

Frequently asked questions

What does a DMARC checker do?

A DMARC checker looks up the TXT record at _dmarc.<domain>, verifies that it exists and is unique, parses every tag and checks the values against the DMARC specification. It then explains the policy in plain language and lists problems such as invalid tags, missing reporting addresses or a weak policy.

Where is the DMARC record published?

The record is a TXT record at the _dmarc subdomain of your domain, for example _dmarc.example.com. You add it in the DNS settings of your domain registrar or DNS provider.

Which DMARC policy should I use?

Start with p=none and a rua address to collect reports. When all legitimate services pass SPF or DKIM with alignment, switch to p=quarantine and then to p=reject. Only p=quarantine and p=reject actually protect the domain from spoofing.

Do I need DMARC if I already have SPF and DKIM?

Yes. SPF and DKIM authenticate a message, but they do not tell receivers what to do when authentication fails, and they do not check the visible From address. DMARC adds alignment, a policy and reporting. Google and Yahoo require DMARC for bulk senders.

Why does my subdomain show the policy of the main domain?

If a subdomain has no own DMARC record, receivers use the record of the organizational domain. The sp tag in that record defines the policy for subdomains; if sp is missing, the p value applies.

How long does it take for a DMARC change to appear?

DNS changes usually propagate within minutes, but cached answers can live as long as the TTL of the old record, often up to a few hours. Run the check again after the TTL expires.

Is this DMARC checker free and private?

Yes. The tool is free with no registration, and we do not store or log the domains you check. Results come directly from public DNS.

More free email tools