Skip to content
Free email tool

DMARC policy checker.

DMARC tells receivers what to do with mail that fails authentication: p=none to monitor, p=quarantine to send it to spam, p=reject to refuse it. Look up a domain's direct or inherited policy.

What this check can tell you

The result shows the record published at _dmarc on the domain you enter. When there is none, it shows the policy inherited from the organizational domain. It marks the policy as direct, inherited, missing, or invalid, then grades the policy, the reporting address, pct, and the alignment and subdomain tags when present.

Limit: DNS inspection cannot prove SPF or DKIM alignment for a real email. It only reports the public policy receivers can apply.

How to read the DMARC result

The first line says where the policy comes from. The findings under it grade the tags.

Direct policy
A valid v=DMARC1 record at _dmarc on the domain you entered. Receivers apply this one.
Inherited policy
No record at that name, so receivers use the organizational domain's. The result names that domain and shows its record. Read its sp= tag, which sets the policy for subdomains.
No DMARC policy
Warning. Nothing direct and nothing inherited, so receivers have no instruction for mail that fails authentication.
Invalid or duplicate record
Fail. A TXT record at _dmarc that does not start with v=DMARC1, or more than one record. Receivers ignore it.
The p= policy
reject and quarantine pass. none warns because it only monitors. A missing or invalid p= fails.
Reporting and pct
A missing rua address warns, because you get no visibility into who sends as your domain. A pct below 100 warns that only part of failing mail is enforced.

From p=none to p=reject

Publish p=none with an rua address first. Receivers send aggregate reports that list every source sending as your domain, with its SPF and DKIM results. Work through each legitimate source until its mail passes aligned SPF or DKIM, then move to p=quarantine. Raise it to p=reject when the reports stay clean.

A message passes DMARC when SPF or DKIM passes and the passing domain aligns with the From domain. Inspect each side with the SPF checker and the DKIM checker. To see all three records for a domain at once, use the email authentication checker.

An annotated DMARC record

An enforcing policy with reporting and relaxed alignment.

Example DMARC record
_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r"

What each part does

v=DMARC1
The version tag. It must come first, or receivers ignore the record.
p=quarantine
What receivers do with mail that fails DMARC: send it to spam.
pct=100
Apply the policy to all failing mail. 100 is the default.
rua=mailto:...
Where aggregate reports go.
adkim=r; aspf=r
Relaxed alignment, the default: the authenticated domain only needs to share the From domain's organizational domain. s requires an exact match.

Common DMARC problems and fixes

Stuck at p=none
Monitoring does not block spoofing. Read your reports, fix the senders that fail, and step up to quarantine and then reject.
Record at the wrong name
The record must sit at the _dmarc label. Some DNS panels append the domain, so entering the full name creates _dmarc.example.com.example.com. Enter only _dmarc.
Two DMARC records
Delete the extra. Keep one record with the policy you want.
v=DMARC1 is not first
A tag or stray text before v=DMARC1 makes the record invalid. Make it the first thing in the value.
No reports arrive
Check the mailto: spelling. If the address is on another domain, that domain must publish a record that authorizes your reports, or receivers withhold them.
SPF and DKIM pass but DMARC fails
The passing domain does not align with your From domain. A third-party sender often uses its own return-path and signing domain. Turn on signing and return-path with your own domain.

DMARC questions

Related Resources