Look up a domain’s DMARC record, validate every tag and see exactly what to fix to protect the domain from spoofing and phishing.
DMARC (Domain-based Message Authentication, Reporting and Conformance) is an email authentication standard defined in RFC 7489. It builds on SPF and DKIM and lets a domain owner tell receiving mail servers what to do with messages that claim to come from the domain but fail authentication.
A DMARC record is a TXT record published at _dmarc.yourdomain.com. It contains a policy (none, quarantine or reject), the addresses where receivers should send reports, and optional settings for alignment and subdomains. Since 2024 Google and Yahoo require a DMARC record from everyone who sends bulk email, so a missing record now directly hurts deliverability.
A typical record for a domain that is ready for full enforcement looks like this:
v=DMARC1; p=reject; sp=reject; rua=mailto:dmarc-reports@example.com; adkim=s; aspf=s; pct=100
It rejects every message that fails both SPF and DKIM alignment, applies the same policy to subdomains and sends daily aggregate reports to the given mailbox.
Move gradually: publish p=none with a rua address, review the reports for a few weeks, fix SPF and DKIM for every legitimate service, then switch to quarantine and finally to reject. The pct tag lets you apply the policy to a percentage of mail while you roll out.
DMARC passes when a message passes SPF or DKIM and the authenticated domain aligns with the domain in the visible From address. That is why a correct DMARC setup always starts with valid SPF and DKIM records. Use our SPF checker and DKIM checker to verify them, then send a test message to a temporary TempBox address to see the real authentication results in the headers.
A DMARC checker looks up the TXT record at _dmarc.<domain>, verifies that it exists and is unique, parses every tag and checks the values against the DMARC specification. It then explains the policy in plain language and lists problems such as invalid tags, missing reporting addresses or a weak policy.
The record is a TXT record at the _dmarc subdomain of your domain, for example _dmarc.example.com. You add it in the DNS settings of your domain registrar or DNS provider.
Start with p=none and a rua address to collect reports. When all legitimate services pass SPF or DKIM with alignment, switch to p=quarantine and then to p=reject. Only p=quarantine and p=reject actually protect the domain from spoofing.
Yes. SPF and DKIM authenticate a message, but they do not tell receivers what to do when authentication fails, and they do not check the visible From address. DMARC adds alignment, a policy and reporting. Google and Yahoo require DMARC for bulk senders.
If a subdomain has no own DMARC record, receivers use the record of the organizational domain. The sp tag in that record defines the policy for subdomains; if sp is missing, the p value applies.
DNS changes usually propagate within minutes, but cached answers can live as long as the TTL of the old record, often up to a few hours. Run the check again after the TTL expires.
Yes. The tool is free with no registration, and we do not store or log the domains you check. Results come directly from public DNS.