No DMARC record found: how to add one
What a missing DMARC record means, why mailbox providers now expect one, and how to add a safe first record at _dmarc on any DNS host.
By the Domain Health Hub team · Updated
- DMARC lives in a TXT record at _dmarc.<domain>. Without it, receivers have no instructions for email that fails SPF and DKIM.
- You also get no reports, so you can't see who is sending email as the domain.
- Start with p=none and a report address. Nothing is blocked while you read the reports.
What it means
A receiving mail server looks for a TXT record at _dmarc.example.com when it gets an email from example.com. We looked there and found nothing starting v=DMARC1. So the domain makes no statement about what should happen to email that fails SPF and DKIM, and asks for no reports.
Why it matters
Without DMARC, anyone can put the domain in the From address of a phishing email and each receiver decides for itself what to do with it. Gmail, Yahoo and Microsoft's consumer services now require a DMARC record (at least p=none) from anyone sending in bulk, and many filters treat its absence as a mark against everyday email too. You also lose the aggregate reports that show every service sending as the domain, which is how you find the forgotten ones before you tighten anything.
How to confirm it
Run the domain through the free checker. It looks up _dmarc directly, so it isn't fooled by a record added at the wrong name, such as on the domain root.
How to fix it
Add one TXT record. A safe first record looks like this:
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com
Use an address that someone, or a service, actually reads: reports are XML attachments and a busy domain gets dozens a day. Once the reports show every genuine sender passing, move on to quarantine and reject, as described in moving off p=none.
Cloudflare DNS
- Open the domain in the Cloudflare dashboard and go to DNS, then Records.
- Add a record of type TXT with the name
_dmarc. Cloudflare adds the domain for you. - Paste the record as the content and save.
Microsoft 365
Microsoft 365 doesn't publish DMARC for your own domain: the record goes wherever the domain's DNS is hosted (your registrar, Cloudflare or similar). Only the onmicrosoft.com domain, or a domain whose DNS Microsoft hosts, is managed in the Microsoft 365 admin centre. Turn on DKIM in the Defender portal before you tighten the policy, so Microsoft 365 email passes on DKIM as well as SPF.
Google Workspace
The same applies: add the TXT record at your DNS host. Make sure Gmail is signing with DKIM for your domain first (Admin console, Apps, Google Workspace, Gmail, Authenticate email), or forwarded email will fail DMARC once you move past p=none.
Questions
Will adding p=none affect my email?
No. p=none asks receivers to deliver as normal and send you reports. It changes nothing about delivery.
Does each subdomain need its own record?
No. Receivers fall back to the organisational domain's record, and its sp= tag sets the policy for subdomains. Add a subdomain record only when it needs a different policy.
Hear about it the day it breaks.
Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.