Skip to content
Free, no sign-up

DMARC record checker

See whether a domain has a valid DMARC record, what its policy does in plain English, and where its reports are going. Free, no sign-up.

What this checks

  • Whether a DMARC record exists at _dmarc, and that there's exactly one
  • The policy (none, quarantine or reject) and what it means for spoofed email
  • pct, the subdomain policy and the SPF and DKIM alignment modes
  • Which domains receive the aggregate reports, or that nobody does
  • For a subdomain, whether it inherits the main domain's record

An example, explained

TXT record at _dmarc.example.co.uk
v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc@example.co.uk; adkim=r; aspf=r
p=quarantine
Email that fails DMARC goes to spam.
pct=100
The policy applies to all failing email (100 is the default).
rua=
Where receivers send daily aggregate reports.
adkim, aspf
Alignment: r (relaxed) allows subdomains to match, s (strict) doesn't.

What a DMARC check tells you

DMARC tells receiving mail servers what to do with email that claims to be from a domain but fails both SPF and DKIM alignment, and asks them to send reports on what they saw. The record lives in DNS as a TXT record at _dmarc. followed by the domain.

The three policies

  • p=none: report only. Spoofed email is still delivered. It's the right place to start, so you can see every service sending as the domain before enforcing anything, but it isn't protection.
  • p=quarantine: failing email goes to spam.
  • p=reject: failing email is refused. This is the goal for most domains, and for every domain that never sends email at all.

Common problems

  • No record: receivers have no instructions, and you get no reports. Gmail, Yahoo and Microsoft now expect at least p=none from bulk senders.
  • Two records: receivers ignore both. Merge them into one.
  • No rua address: nobody hears about the services sending as the domain, so there's no safe way to move past p=none.
  • pct below 100: the policy applies to only part of the failing email. Fine for a week or two while tightening; not as a resting place.

DMARC depends on SPF and DKIM, so the full result below the DMARC section shows those too. For the background, read what DMARC is and how to set it up, or build a record with the DMARC record generator.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

Where does a DMARC record go?

In DNS, as a TXT record on the name _dmarc in front of the domain, for example _dmarc.example.co.uk. There must be exactly one.

Is p=none good enough?

It's a starting point, not protection: spoofed email is still delivered. Use the reports to find every service that sends as the domain, fix their SPF and DKIM, then move to quarantine and reject.

Why does a subdomain show the main domain's record?

When a subdomain has no DMARC record of its own, receivers use the main (organisational) domain's record, with its sp= policy if it has one. The checker shows when that happens.

Do you keep the domains I check?

No. Results are held in memory for 10 minutes so a refresh doesn't run every check again, then dropped.

Can I see the reports themselves?

Not from a one-off check. Point the domain's rua address at Domain Health Hub, or let us host the record, and the reports appear in your dashboard grouped by sending service.

Watch every client's DMARC, every day.

Start a free 28-day trial: up to 3 domains, no card needed.