DMARC record generator

Pick what you want receivers to do and get the DMARC record to paste. Give us the domain as well and we edit the record it publishes today, keeping every tag we did not come here to change.

Optional, and the reason to give it: we read the DMARC record this domain publishes right now and edit that one, keeping every tag we did not come here to change.

What do you want receivers to do?

Any mailbox you read. Receivers mail one XML file per day each to whatever address this tag names, and an address on this domain needs no further setup.

Leave this empty and the record does nothing. p=none enforces nothing by design, so the reports are the entire point of publishing it. A monitoring record with no rua= tag asks no receiver for anything and tells you nothing.

Any mailbox works. Ours is one you do not have to open: we parse every report and mail you one summary a week, with an alert the day a new sender fails on the paid plans.

Alignment, subdomains and pct
Subdomain policy
DKIM alignment
SPF alignment

Leave it empty for all of it. Anything lower delivers the rest as if the policy were none.

What a DMARC record generator gives you

What does a DMARC record generator do? It writes the single TXT record at _dmarc.yourdomain.com that tells receivers what to do with mail claiming your domain that fails both SPF and DKIM alignment, and where to send the daily reports naming everything that sent as you.

Two tags carry the record. p= is the instruction: none means deliver failing mail anyway, quarantine means send it to spam, reject means refuse it. rua= is the address receivers mail aggregate reports to. Everything else is a refinement on those two, which is why the rest of the form is folded away.

This one edits the record you already have

Give the page your domain and it reads what is published. The reporting address is added to the rua= list rather than written over it, so a reporting tool already receiving your reports keeps receiving them. The policy is rewritten in place. Tags this page did not come to change, including pct, sp, fo, ruf, ri, adkim and aspf, are copied through byte for byte, and the difference between the two records is marked so you can see that for yourself.

A domain carries exactly one DMARC record. A second one at the same name is a configuration error, and receivers ignore both, so the record above is a replacement for the published one rather than something to publish beside it.

Start at p=none, and move once the reports say so

Is p=none worth publishing? Yes, and it is the only safe first record. Enforcement blocks the senders that fail alignment, and on most domains that list includes at least one the owner did not know about: the invoicing app, the CRM, the survey tool a contractor connected. At p=none receivers deliver that mail and report it, which is how you find out. Publishing p=reject on a domain whose senders have never been measured is how a company blocks its own invoices. The DMARC setup guide covers the ramp and the numbers to check before each step.

The reports are XML, one file per receiver per day, sent to whatever mailbox rua= names. Reading one by hand covers what is in them, and the report analyzer reads one for you when it lands.

SPF and DKIM decide whether the policy hurts

DMARC runs no check of its own. It reads the SPF and DKIM results, and it passes when either one passed and the domain that passed matches the domain in the From line, which is the part called alignment. So a platform can pass SPF under its own name and still fail DMARC for you. Before tightening the policy, publish both records for every sender: the SPF record generator builds or merges the SPF half, the provider pages carry the DKIM half per platform, and the combined checker reads all three back from live DNS.

A DMARC record asks for reports somebody has to read

The rua= tag works with any mailbox. What arrives in it is XML, one file per receiver per day, and a month of unread ones is a month of not knowing which of your senders failed. We parse them and mail you one summary a week, with an alert the day a new sender first fails on the paid plans. Pro covers 10 domains for $19 a month.

Send them to us instead

No card · 12+ months of history · The free plan does not expire

The other tools