DomainCanary Start free

DMARC record checker

Look up the DMARC record published on any domain to verify policy enforcement, alignment rules, and daily aggregate reporting.

A DMARC record publishes your policy for unauthenticated email and tells inbox providers where to send feedback. It lives as a DNS TXT record at _dmarc.yourdomain.com and connects your visible From address to SPF and DKIM. Use our DMARC record generator if you need to create a new record.

Questions

What do the p= and rua= tags do in a DMARC record?

The p= tag tells receivers what to do with mail that fails authentication: none delivers it, quarantine sends it to spam, and reject blocks it at the boundary. The rua= tag specifies the email address that receives your daily XML aggregate reports.

How should you roll out a DMARC policy safely?

Start at p=none to collect aggregate reports and inventory your senders. Once you configure SPF and DKIM for every service, switch to p=quarantine so failed mail drops into spam. Move to p=reject only when you know all legitimate mail passes. Follow our guide to DMARC setup.

Why can moving to p=reject too early break delivery?

If an active billing tool, helpdesk, or marketing service lacks authentication, a strict policy blocks those messages at the boundary. Receivers reject anything that fails authentication under your domain name. Review your data with our guide on how to read a DMARC aggregate report before enforcing rejection.

Why does DMARC fail even when SPF and DKIM pass?

DMARC requires identifier alignment. The domain in your visible From header must match the envelope Return-Path for SPF or the d= tag for DKIM. Third-party platforms often sign with their own shared domains by default. Check our DMARC alignment guide and test your senders with our SPF checker.

What are the np= and psd= tags in DMARC?

The np= tag sets the policy for mail that fails DMARC from subdomains that don't exist in DNS. The psd=y tag marks your domain as a public suffix, like co.uk, so receivers use a base domain one level below it. In RFC 9989, relaxed alignment means your From address and SPF or DKIM share that base domain.

Stop reading raw DMARC XML reports by hand

Mailbox providers generate XML files containing IP addresses, volumes, and authentication pass rates for your domain. DomainCanary digests that data into one concise weekly summary, highlighting what changed and what needs attention. Your first domain is free, with per-source totals kept for the life of the account.

Monitor your domain free

Free for your first domain · No card · Per-source totals kept for life

The other tools