My Tool Studio
Webmaster

DMARC Checker

A DMARC checker reads a domain's DMARC record and explains what it tells receiving mail servers to do with mail that fails authentication. Enter a domain or email address and press Check DMARC. The tool finds the record at _dmarc, falls back to the parent domain for subdomains, and explains every tag: policy, subdomain policy, percentage, report addresses, alignment and more. It flags syntax errors, a missing policy, a percentage below 100 and report addresses on other domains that have not authorized them. It also probes more than 30 common DKIM selectors and shows each key's type and size, and reports SPF and BIMI status. When the record is missing or weak, the built-in generator writes a new one you can copy straight into your DNS.

Always freeNo sign upRuns in your browser

Checked together with 30+ common selectors.

DMARC record generator
TXT record at _dmarc.yourdomain.com
v=DMARC1; p=none

Start with p=none and a rua address, read the reports for a few weeks, fix any sender that fails, then step up to quarantine and reject.

How to use

01

Enter the domain

Type example.com or an email address. If you know your DKIM selector, such as selector1 or google, enter it too; it is checked along with the common ones.

02

Read the policy and checks

The cards show the DMARC record, policy, SPF and DKIM status. The tags table explains each value, and the checks list names every problem with a short fix.

03

Generate or update the record

Open the generator, choose a policy and a report address, and copy the TXT record for _dmarc at your domain into your DNS. Run the check again once the TTL has passed.

Why DMARC Checker

DMARC tags at a glance

A DMARC record is a list of tag=value pairs separated by semicolons. Only v and p are required. The checker explains every tag it finds and flags the ones with invalid values.

TagMeaningExample
vVersion, always firstv=DMARC1
pPolicy for the domainp=reject
spPolicy for subdomainssp=quarantine
pctShare of failing mail the policy applies topct=100
ruaWhere aggregate reports gorua=mailto:dmarc@example.com
rufWhere failure reports go (rarely sent now)ruf=mailto:dmarc@example.com
adkim / aspfDKIM and SPF alignment: r relaxed, s strictadkim=s
foWhen to send failure reportsfo=1

A safe path from p=none to p=reject

Jumping straight to reject can block your own invoices or newsletters if one service is not set up yet. Move in stages and let the reports tell you when it is safe.

  • Publish v=DMARC1; p=none; rua=mailto:your-report-address and wait two to four weeks.
  • Read the reports and list every service that sends as your domain.
  • Set up SPF and DKIM with your own domain at each of those services.
  • Move to p=quarantine, optionally with pct=25 at first, then raise pct to 100.
  • When reports show only your own services passing, move to p=reject.
  • Keep the rua address so you notice new services or spoofing attempts later.

Common questions

What is DMARC and how does it work?
DMARC is a TXT record that tells receiving servers what to do when a message claiming to be from your domain fails both SPF and DKIM, or passes them only for some other domain. It also asks receivers to send you reports, so you can see every service that sends mail using your name.
What is the difference between p=none, p=quarantine and p=reject?
p=none only collects reports and changes nothing about delivery. p=quarantine asks receivers to put failing mail in spam or junk. p=reject asks them to refuse it outright. Start with none, fix the senders the reports reveal, then step up to quarantine and reject.
Where do I publish a DMARC record?
As a TXT record on the name _dmarc in front of your domain, so _dmarc.example.com. In most DNS panels you enter _dmarc as the host or name and the record text as the value. There must be exactly one such record.
Do I need DMARC to send email to Gmail and Yahoo?
If you send in bulk, yes. Since February 2024, Google and Yahoo require senders of 5,000 or more messages a day to their users to publish DMARC, at least p=none, along with SPF and DKIM. Smaller senders are strongly encouraged to do the same, and it helps deliverability for everyone.
What are DMARC aggregate reports and where do they go?
Aggregate reports are daily XML files that big mailbox providers send to the address in your rua tag. Each one lists the IPs that sent mail as your domain and whether SPF, DKIM and DMARC passed. They are hard to read raw, so many people send them to a report analysis service.
Why does the checker warn about my rua address on another domain?
When reports go to a domain other than your own, that domain must publish a record saying it accepts them, at yourdomain.com._report._dmarc.theirdomain.com. Report services set this up for their customers. Without it, many providers quietly skip sending reports there.
Why can the DMARC checker not find my DKIM record?
DKIM keys live under a selector name that each sending service picks, such as selector1 for Microsoft 365 or google for Google Workspace. The tool tries over 30 common ones. If yours is custom, open an email you sent, find the DKIM-Signature header, and enter the value after s= as your selector.
What DKIM key size should I use?
2048-bit RSA is the current recommendation, and most providers now default to it. 1024-bit keys still work but are considered weak, and keys smaller than that should be replaced at once. The checker estimates the size of every key it finds.
Does each subdomain need its own DMARC record?
No. Subdomains without a record inherit the parent domain's policy, or its sp= policy when one is set. Give a subdomain its own record only when it needs a different policy or different report addresses, for example a marketing subdomain still on p=none.
What is BIMI, and does it need DMARC?
BIMI lets supporting inboxes show your brand logo next to your messages. It is published as a TXT record at default._bimi on your domain and only works when DMARC is set to quarantine or reject. Some providers, including Gmail, also require a paid certificate for the logo.

More Webmaster tools

View all