Build a DMARC record you can paste into DNS

Pick a policy, add the address that should receive reports, and copy the finished TXT record. Every tag is explained as you go, so you know what you are publishing.

Optional
100%
Any mailbox you own. Separate several with commas.
Show advanced options
Host
_dmarc.yourdomain.com
Type
TXT
Value
v=DMARC1; p=none

Add this as a TXT record in your DNS. Most panels want only the part before your domain in the Host field, so enter _dmarc there if the panel appends the domain itself.

What this record does

  • v=DMARC1Version. Always DMARC1.
  • p=noneMonitor only. Mail that fails is still delivered; you only receive reports.

Without a report address you will never learn who is sending as your domain. Add one, even if it is just your own inbox.

Where do I add a DMARC record?

In the DNS settings of whoever hosts your domain's zone, which is usually your registrar or Cloudflare. Add a new record, choose TXT as the type, enter _dmarc as the host or name, and paste the value from above. Some panels want the full name _dmarc.yourdomain.com and some append the domain themselves; if you see _dmarc.yourdomain.com.yourdomain.com in the list afterwards, shorten the host to _dmarc. Leave TTL at the default.

One domain gets one DMARC record. If a record already exists, edit it rather than adding a second; receivers ignore DMARC completely when they find two. After saving, wait a few minutes and confirm it with the DMARC checker.

How do I roll out DMARC without blocking my own mail?

Start with monitor only and a report address. For two to four weeks, read the reports: every service that sends as your domain shows up there, including the invoicing tool, the newsletter platform and the CRM nobody remembered. For each one that fails, either add it to SPF, turn on DKIM signing in its settings with your domain, or stop it sending as you. When the reports show only passes from sources you recognise, change the policy to send to spam. A few weeks after that, change it to reject.

The share slider exists for the nervous: setting it to 25 applies the new policy to a quarter of failing mail while the rest stays one step softer, which lets you spot a problem before it hits everything. Most domains can skip it and go straight to 100.

What do the advanced DMARC tags do?

Alignment controls how closely the domain in a passing SPF or DKIM check must match the domain people see in the From line. Relaxed accepts a subdomain, so mail signed by news.yourdomain.com aligns with yourdomain.com. Strict demands an exact match. Relaxed is the default and the right answer unless your security team has asked for strict.

Forensic reports were meant to send you a copy of each failing message. Gmail, Microsoft and Yahoo do not send them for privacy reasons, so the address rarely receives anything; it does no harm to leave it empty. If you want to see what a real report contains, the DMARC report analyzer has a sample.

Or let Faivelo write it into your DNS.

Add your domain and the DMARC record goes in through your registrar together with MX, SPF and DKIM, with reports delivered to a mailbox on your own domain.

Set up my domain

Free 14-day trial. No card needed.

Questions people ask