Back to Free Tools
DMARC Record Checker
Look up and validate your domain's DMARC record. Parse every tag, check policy strength, alignment and aggregate reporting.
Check a DMARC record
Try:
What is a DMARC record?
A DMARC record is a DNS TXT record published at _dmarc.<your-domain> that tells receiving mail servers what to do when SPF or DKIM fails for your domain, and where to send aggregate reports. It is the policy and reporting layer on top of SPF and DKIM.
A typical DMARC record looks like this:
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; adkim=s; aspf=s; pct=100What this DMARC checker validates
- Whether a
v=DMARC1record is published at_dmarc.<domain> - That only one DMARC record exists (RFC 7489 forbids multiple)
- Syntax of every tag (
v,p,sp,rua,ruf,adkim,aspf,pct,fo) - Strength of the
p=policy (none vs quarantine vs reject) - Presence and validity of
ruaaggregate-report destinations - Alignment mode for SPF and DKIM (relaxed vs strict)
- Use of
pct<100that weakens enforcement - Subdomain policy gaps via
sp=
DMARC tag reference
| Tag | Required | Meaning |
|---|---|---|
v | Yes | Protocol version. Must be DMARC1 and appear first. |
p | Yes | Policy for the organizational domain: none, quarantine, or reject. |
sp | No | Policy for subdomains. Defaults to p if omitted. |
rua | No | Email address(es) for aggregate XML reports. mailto: URI list. |
ruf | No | Email address(es) for forensic/failure reports. Rarely supported now. |
adkim | No | DKIM alignment mode: r (relaxed, default) or s (strict). |
aspf | No | SPF alignment mode: r (relaxed, default) or s (strict). |
pct | No | Percentage of failing mail the policy applies to (0–100). Defaults to 100. |
fo | No | Failure reporting options: 0, 1, d, s. Defaults to 0. |
rf | No | Failure report format. Defaults to afrf. |
ri | No | Aggregate report interval in seconds. Defaults to 86400 (daily). |
p=none vs p=quarantine vs p=reject
| Policy | Effect | When to use |
|---|---|---|
p=none | Receivers deliver as usual; aggregate reports flow. | Day-1 monitoring while you discover senders. |
p=quarantine | Failing mail is delivered to spam/junk. | Once known senders are aligned and reports are clean. |
p=reject | Failing mail is dropped at the receiver. | Final, enforced state. Required for full anti-spoofing. |
How to fix common DMARC problems
- Publish a
ruamailbox you actually read before raising policy - Roll forward gradually:
p=none→p=quarantine; pct=10→ ramppctto 100 →p=reject - Set an explicit
sp=so subdomains are not left at the default - Fix alignment by enabling custom DKIM (your own d=) at every ESP, not relying on shared signatures
- Remove
ruf=if you don't have a forensic-report pipeline — most receivers ignore it - Never publish two DMARC TXT records on
_dmarc— receivers treat that as no policy
Frequently asked questions
Related free tools
References
Go beyond one-off checks
Safer Sender continuously monitors your domain's DMARC, SPF and DKIM, classifies every sender, and guides you safely from p=none to p=reject.