Checked together with 30+ common selectors.
DMARC record generator
v=DMARC1; p=noneStart with p=none and a rua address, read the reports for a few weeks, fix any sender that fails, then step up to quarantine and reject.
How to use
Enter the domain
Type example.com or an email address. If you know your DKIM selector, such as selector1 or google, enter it too; it is checked along with the common ones.
Read the policy and checks
The cards show the DMARC record, policy, SPF and DKIM status. The tags table explains each value, and the checks list names every problem with a short fix.
Generate or update the record
Open the generator, choose a policy and a report address, and copy the TXT record for _dmarc at your domain into your DNS. Run the check again once the TTL has passed.
Why DMARC Checker
- Finds the DMARC record, explains every tag in plain English and flags syntax mistakes.
- Checks that external report addresses are authorized, and falls back to the parent domain for subdomains.
- Probes 30+ common DKIM selectors and shows each key's type and size, plus SPF and BIMI status.
- A built-in generator writes a new DMARC record you can copy straight into your DNS.
DMARC tags at a glance
A DMARC record is a list of tag=value pairs separated by semicolons. Only v and p are required. The checker explains every tag it finds and flags the ones with invalid values.
| Tag | Meaning | Example |
|---|---|---|
| v | Version, always first | v=DMARC1 |
| p | Policy for the domain | p=reject |
| sp | Policy for subdomains | sp=quarantine |
| pct | Share of failing mail the policy applies to | pct=100 |
| rua | Where aggregate reports go | rua=mailto:dmarc@example.com |
| ruf | Where failure reports go (rarely sent now) | ruf=mailto:dmarc@example.com |
| adkim / aspf | DKIM and SPF alignment: r relaxed, s strict | adkim=s |
| fo | When to send failure reports | fo=1 |
A safe path from p=none to p=reject
Jumping straight to reject can block your own invoices or newsletters if one service is not set up yet. Move in stages and let the reports tell you when it is safe.
- Publish v=DMARC1; p=none; rua=mailto:your-report-address and wait two to four weeks.
- Read the reports and list every service that sends as your domain.
- Set up SPF and DKIM with your own domain at each of those services.
- Move to p=quarantine, optionally with pct=25 at first, then raise pct to 100.
- When reports show only your own services passing, move to p=reject.
- Keep the rua address so you notice new services or spoofing attempts later.