DMARC policy checker.
DMARC tells receivers what to do with mail that fails authentication: p=none to monitor, p=quarantine to send it to spam, p=reject to refuse it. Look up a domain's direct or inherited policy.
What this check can tell you
The result shows the record published at _dmarc on the domain you enter. When there is none, it shows the policy inherited from the organizational domain. It marks the policy as direct, inherited, missing, or invalid, then grades the policy, the reporting address, pct, and the alignment and subdomain tags when present.
Limit: DNS inspection cannot prove SPF or DKIM alignment for a real email. It only reports the public policy receivers can apply.
How to read the DMARC result
The first line says where the policy comes from. The findings under it grade the tags.
- Direct policy
- A valid
v=DMARC1record at_dmarcon the domain you entered. Receivers apply this one. - Inherited policy
- No record at that name, so receivers use the organizational domain's. The result names that domain and shows its record. Read its
sp=tag, which sets the policy for subdomains. - No DMARC policy
- Warning. Nothing direct and nothing inherited, so receivers have no instruction for mail that fails authentication.
- Invalid or duplicate record
- Fail. A TXT record at
_dmarcthat does not start withv=DMARC1, or more than one record. Receivers ignore it. - The p= policy
rejectandquarantinepass.nonewarns because it only monitors. A missing or invalidp=fails.- Reporting and pct
- A missing
ruaaddress warns, because you get no visibility into who sends as your domain. Apctbelow 100 warns that only part of failing mail is enforced.
From p=none to p=reject
Publish p=none with an rua address first. Receivers send aggregate reports that list every source sending as your domain, with its SPF and DKIM results. Work through each legitimate source until its mail passes aligned SPF or DKIM, then move to p=quarantine. Raise it to p=reject when the reports stay clean.
A message passes DMARC when SPF or DKIM passes and the passing domain aligns with the From domain. Inspect each side with the SPF checker and the DKIM checker. To see all three records for a domain at once, use the email authentication checker.
An annotated DMARC record
An enforcing policy with reporting and relaxed alignment.
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; pct=100; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r"What each part does
v=DMARC1- The version tag. It must come first, or receivers ignore the record.
p=quarantine- What receivers do with mail that fails DMARC: send it to spam.
pct=100- Apply the policy to all failing mail. 100 is the default.
rua=mailto:...- Where aggregate reports go.
adkim=r; aspf=r- Relaxed alignment, the default: the authenticated domain only needs to share the From domain's organizational domain.
srequires an exact match.
Common DMARC problems and fixes
- Stuck at p=none
- Monitoring does not block spoofing. Read your reports, fix the senders that fail, and step up to quarantine and then reject.
- Record at the wrong name
- The record must sit at the
_dmarclabel. Some DNS panels append the domain, so entering the full name creates_dmarc.example.com.example.com. Enter only_dmarc. - Two DMARC records
- Delete the extra. Keep one record with the policy you want.
- v=DMARC1 is not first
- A tag or stray text before
v=DMARC1makes the record invalid. Make it the first thing in the value. - No reports arrive
- Check the
mailto:spelling. If the address is on another domain, that domain must publish a record that authorizes your reports, or receivers withhold them. - SPF and DKIM pass but DMARC fails
- The passing domain does not align with your From domain. A third-party sender often uses its own return-path and signing domain. Turn on signing and return-path with your own domain.