DMARC record generator
Pick what you want receivers to do and get the DMARC record to paste. Give us the domain as well and we edit the record it publishes today, keeping every tag we did not come here to change.
What a DMARC record generator gives you
What does a DMARC record generator do? It writes the single TXT record at
_dmarc.yourdomain.com that tells receivers what to do with mail claiming your
domain that fails both SPF and DKIM alignment, and where to send the daily reports naming
everything that sent as you.
Two tags carry the record. p= is the instruction:
none means deliver failing mail anyway, quarantine means send it to
spam, reject means refuse it. rua= is the address receivers mail
aggregate reports to. Everything else is a refinement on those two, which is why the rest of
the form is folded away.
This one edits the record you already have
Give the page your domain and it reads what is published. The reporting address is added to the
rua= list rather than written over it, so a reporting tool already receiving your
reports keeps receiving them. The policy is rewritten in place. Tags this page did not come to
change, including pct, sp, fo, ruf,
ri, adkim and aspf, are copied through byte for byte,
and the difference
between the two records is marked so you can see that for yourself.
A domain carries exactly one DMARC record. A second one at the same name is a configuration error, and receivers ignore both, so the record above is a replacement for the published one rather than something to publish beside it.
Start at p=none, and move once the reports say so
Is p=none worth publishing? Yes, and it is the only safe first record.
Enforcement blocks the senders that fail alignment, and on most domains that list includes at
least one the owner did not know about: the invoicing app, the CRM, the survey tool a
contractor connected. At p=none receivers deliver that mail and report it, which
is how you find out. Publishing p=reject on a domain whose senders have never been
measured is how a company blocks its own invoices.
The DMARC setup guide covers the ramp and the numbers to
check before each step.
The reports are XML, one file per receiver per day, sent to whatever mailbox
rua= names.
Reading one by hand covers what is in them,
and the report analyzer reads one for you when it
lands.
SPF and DKIM decide whether the policy hurts
DMARC runs no check of its own. It reads the SPF and DKIM results, and it passes when either one passed and the domain that passed matches the domain in the From line, which is the part called alignment. So a platform can pass SPF under its own name and still fail DMARC for you. Before tightening the policy, publish both records for every sender: the SPF record generator builds or merges the SPF half, the provider pages carry the DKIM half per platform, and the combined checker reads all three back from live DNS.
A DMARC record asks for reports somebody has to read
The rua= tag works with any mailbox. What arrives in
it is XML, one file per receiver per day, and a month of unread ones is a
month of not knowing which of your senders failed. We parse them and mail
you one summary a week, with an alert the day a new sender first fails on
the paid plans. Pro covers 10 domains for $19 a month.
No card · 12+ months of history · The free plan does not expire