Back to Free Tools

    DMARC Record Checker

    Look up and validate your domain's DMARC record. Parse every tag, check policy strength, alignment and aggregate reporting.

    Check a DMARC record

    Try:

    What is a DMARC record?

    A DMARC record is a DNS TXT record published at _dmarc.<your-domain> that tells receiving mail servers what to do when SPF or DKIM fails for your domain, and where to send aggregate reports. It is the policy and reporting layer on top of SPF and DKIM.

    A typical DMARC record looks like this:

    v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; adkim=s; aspf=s; pct=100

    What this DMARC checker validates

    • Whether a v=DMARC1 record is published at _dmarc.<domain>
    • That only one DMARC record exists (RFC 7489 forbids multiple)
    • Syntax of every tag (v, p, sp, rua, ruf, adkim, aspf, pct, fo)
    • Strength of the p= policy (none vs quarantine vs reject)
    • Presence and validity of rua aggregate-report destinations
    • Alignment mode for SPF and DKIM (relaxed vs strict)
    • Use of pct<100 that weakens enforcement
    • Subdomain policy gaps via sp=

    DMARC tag reference

    TagRequiredMeaning
    vYesProtocol version. Must be DMARC1 and appear first.
    pYesPolicy for the organizational domain: none, quarantine, or reject.
    spNoPolicy for subdomains. Defaults to p if omitted.
    ruaNoEmail address(es) for aggregate XML reports. mailto: URI list.
    rufNoEmail address(es) for forensic/failure reports. Rarely supported now.
    adkimNoDKIM alignment mode: r (relaxed, default) or s (strict).
    aspfNoSPF alignment mode: r (relaxed, default) or s (strict).
    pctNoPercentage of failing mail the policy applies to (0–100). Defaults to 100.
    foNoFailure reporting options: 0, 1, d, s. Defaults to 0.
    rfNoFailure report format. Defaults to afrf.
    riNoAggregate report interval in seconds. Defaults to 86400 (daily).

    p=none vs p=quarantine vs p=reject

    PolicyEffectWhen to use
    p=noneReceivers deliver as usual; aggregate reports flow.Day-1 monitoring while you discover senders.
    p=quarantineFailing mail is delivered to spam/junk.Once known senders are aligned and reports are clean.
    p=rejectFailing mail is dropped at the receiver.Final, enforced state. Required for full anti-spoofing.

    How to fix common DMARC problems

    • Publish a rua mailbox you actually read before raising policy
    • Roll forward gradually: p=none → p=quarantine; pct=10 → ramp pct to 100 → p=reject
    • Set an explicit sp= so subdomains are not left at the default
    • Fix alignment by enabling custom DKIM (your own d=) at every ESP, not relying on shared signatures
    • Remove ruf= if you don't have a forensic-report pipeline — most receivers ignore it
    • Never publish two DMARC TXT records on _dmarc — receivers treat that as no policy

    Frequently asked questions

    References

    Go beyond one-off checks

    Safer Sender continuously monitors your domain's DMARC, SPF and DKIM, classifies every sender, and guides you safely from p=none to p=reject.