Build a DMARC record you can paste into DNS
Pick a policy, add the address that should receive reports, and copy the finished TXT record. Every tag is explained as you go, so you know what you are publishing.
Show advanced optionsHide advanced options
- Host
- _dmarc.yourdomain.com
- Type
- TXT
- Value
- v=DMARC1; p=none
Add this as a TXT record in your DNS. Most panels want only the part before your domain in the Host field, so enter _dmarc there if the panel appends the domain itself.
What this record does
- v=DMARC1Version. Always DMARC1.
- p=noneMonitor only. Mail that fails is still delivered; you only receive reports.
Without a report address you will never learn who is sending as your domain. Add one, even if it is just your own inbox.
Where do I add a DMARC record?
In the DNS settings of whoever hosts your domain's zone, which is usually your registrar or Cloudflare. Add a new record, choose TXT as the type, enter _dmarc as the host or name, and paste the value from above. Some panels want the full name _dmarc.yourdomain.com and some append the domain themselves; if you see _dmarc.yourdomain.com.yourdomain.com in the list afterwards, shorten the host to _dmarc. Leave TTL at the default.
One domain gets one DMARC record. If a record already exists, edit it rather than adding a second; receivers ignore DMARC completely when they find two. After saving, wait a few minutes and confirm it with the DMARC checker.
How do I roll out DMARC without blocking my own mail?
Start with monitor only and a report address. For two to four weeks, read the reports: every service that sends as your domain shows up there, including the invoicing tool, the newsletter platform and the CRM nobody remembered. For each one that fails, either add it to SPF, turn on DKIM signing in its settings with your domain, or stop it sending as you. When the reports show only passes from sources you recognise, change the policy to send to spam. A few weeks after that, change it to reject.
The share slider exists for the nervous: setting it to 25 applies the new policy to a quarter of failing mail while the rest stays one step softer, which lets you spot a problem before it hits everything. Most domains can skip it and go straight to 100.
What do the advanced DMARC tags do?
Alignment controls how closely the domain in a passing SPF or DKIM check must match the domain people see in the From line. Relaxed accepts a subdomain, so mail signed by news.yourdomain.com aligns with yourdomain.com. Strict demands an exact match. Relaxed is the default and the right answer unless your security team has asked for strict.
Forensic reports were meant to send you a copy of each failing message. Gmail, Microsoft and Yahoo do not send them for privacy reasons, so the address rarely receives anything; it does no harm to leave it empty. If you want to see what a real report contains, the DMARC report analyzer has a sample.
Or let Faivelo write it into your DNS.
Add your domain and the DMARC record goes in through your registrar together with MX, SPF and DKIM, with reports delivered to a mailbox on your own domain.
Free 14-day trial. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC report analyzerDrop in a DMARC aggregate report and see who is sending as your domain and whether they pass.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.
- SMTP error codesWhat each bounce code means, which provider sends it and how to fix it, one page per code.