Skip to content

Free Tool

DMARC Record Checker

Validate your domain's DMARC record. Analyze your policy strength, check alignment, and get recommendations to improve email security.

Free instant check — no signup required

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email security protocol that protects your domain from being used in email spoofing attacks. It builds on top of SPF and DKIM to give domain owners full control over how their email is authenticated.

Without DMARC, attackers can send phishing emails that appear to come from your domain. DMARC solves this by telling receiving mail servers exactly what to do when authentication fails — and provides reporting so you can monitor unauthorized use of your domain.

Major email providers like Gmail, Yahoo, and Microsoft now require DMARC for bulk senders. Since 2024, Google and Yahoo have required a DMARC record for anyone sending more than 5,000 emails per day.

DMARC Policy Progression

Step 1

p=none

Monitor only. Collect reports to understand your email ecosystem before enforcing.

Step 2

p=quarantine

Failed emails go to spam. Good intermediate step while you verify all senders.

Step 3

p=reject

Maximum protection. Failed emails are blocked entirely. The gold standard for domain security.

Frequently Asked Questions

What is DMARC?
DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email authentication protocol that builds on SPF and DKIM. It lets domain owners specify what happens when an email fails authentication checks — whether to monitor (none), quarantine, or reject the message. DMARC also provides a reporting mechanism so you can see who is sending email on behalf of your domain.
What are the DMARC policy options?
There are three DMARC policies: "p=none" (monitor only — no action taken on failed emails), "p=quarantine" (failed emails go to spam/junk), and "p=reject" (failed emails are blocked entirely). Most organizations start with "none" to gather data, then gradually move to "quarantine" and finally "reject" for maximum protection.
How do I set up DMARC?
Add a TXT record to your DNS at "_dmarc.yourdomain.com". A basic starter record looks like: "v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com". The "rua" tag specifies where aggregate reports should be sent. Start with p=none to monitor, then tighten the policy once you confirm all legitimate email sources pass SPF and DKIM.
Do I need SPF and DKIM before DMARC?
Yes. DMARC requires at least one of SPF or DKIM to be set up (ideally both). DMARC works by checking whether incoming emails pass SPF and/or DKIM alignment. Without these underlying protocols, DMARC has nothing to validate against, and all emails will fail DMARC checks.
What are DMARC aggregate reports?
DMARC aggregate reports (rua) are XML reports sent by receiving mail servers to the email address specified in your DMARC record. They contain data about all emails sent using your domain, including which ones passed and failed SPF/DKIM/DMARC checks. These reports help you identify unauthorized senders and fine-tune your email authentication before enforcing stricter policies.

Complete Your Email Authentication Setup

Need continuous DMARC monitoring?

Get automatic alerts when your DMARC record changes or weakens. Monitor SPF, DKIM, DMARC, and 60 blacklists.

Start Monitoring Free