DMARC record generator

Choose one of 3 policies, add the address that should receive reports and copy the TXT record for _dmarc.<your domain>. Everything runs in your browser.

Your DMARC policy

The domain in the From address of your mail, for example example.com.

Policy for mail that fails (p)

One e-mail address per line. Receivers send a daily XML summary here.

100 is the default. Lower values are used while ramping up quarantine or reject.

Alignment and failure reports

Optional. Few receivers send per-message failure reports.

Failure report options (fo)

Only published together with a ruf address.

Your DMARC record

Host / name
_dmarc
Type
TXT
Value
v=DMARC1; p=none
No rua address: you will not receive reports, so you cannot see who sends with your domain. Add one before you enforce anything.

Staged rollout

  1. Stage 1 of 3, none: nothing changes for your mail. Read the reports and fix SPF and DKIM for every legitimate sender.
  2. Stage 2 of 3, quarantine: failing mail goes to spam. Ramp up with pct if you like, and keep reading the reports.
  3. Stage 3 of 3, reject: failing mail is refused. Only go here when the reports show no legitimate mail failing.

Check the published record with the DMARC checker →

This generator runs in your browser. Nothing you type is sent anywhere.

What goes into a DMARC record

DMARC is a TXT record at _dmarc.<domain>. p is the policy for mail that fails: none (only report), quarantine (treat as suspicious, usually the spam folder) or reject. sp sets a different policy for subdomains. rua is where aggregate reports go, one XML summary per receiver per day; ruf asks for per-message failure reports, which few receivers send. pct applies the policy to a share of failing mail. adkim and aspf choose relaxed (organizational domain) or strict (exact domain) alignment, and fo selects when failure reports are generated.

The generator leaves out tags that are at their default value, so a typical record stays short: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com.

Roll it out in stages: none, quarantine, reject

Start with p=none and a rua address. Nothing changes for your mail, and within days the reports show every system that sends with your domain: the newsletter tool, the invoicing system, the forgotten web form. Fix SPF and DKIM for each legitimate source until the reports show them passing with alignment.

Then move to p=quarantine, optionally with pct=25 and rising, and watch the reports again. When legitimate mail no longer fails, publish p=reject. Rushing to reject without reading reports is the usual way to lose real mail.

Reports sent to another domain

If the rua or ruf address is on a different domain than the one the record is for, that other domain has to agree: it publishes a TXT record v=DMARC1 at <your domain>._report._dmarc.<their domain>. Reporting services set this up for their customers. The generator shows the exact host name when it applies.

How to use this tool

  1. Enter the domain and choose a policy. Start with none. Move to quarantine and then reject once the reports show that legitimate mail passes.
  2. Add report addresses. Add at least one rua address for aggregate reports. Other tags are optional and left out at their defaults.
  3. Copy and publish. Publish the value as a TXT record with the host _dmarc and verify it with the DMARC checker.

Command line equivalent

The same check from a terminal. The commands use example.com: replace it with your own name.

  • Record that is published nowdig _dmarc.example.com TXT +short
  • Authorization record for reports sent to another domaindig example.com._report._dmarc.example.org TXT +short
  • Windowsnslookup -type=TXT _dmarc.example.com

FAQ

How do I create a DMARC record?

Enter your domain, choose the policy (start with none), add a mailbox for aggregate reports and copy the result. Publish it as a TXT record with the host _dmarc.

Which policy should I start with?

p=none with a rua address. It does not affect delivery and gives you the reports you need before you enforce anything.

What is the difference between rua and ruf?

rua receives daily aggregate statistics and is the one you need. ruf requests copies or excerpts of individual failing messages; most large receivers do not send them, for privacy reasons.

Do I need SPF and DKIM before DMARC?

DMARC passes when either SPF or DKIM passes with a domain aligned to the From address. Set up both where you can: DKIM survives forwarding, SPF does not.

Where do I check the record after publishing?

Use the DMARC checker on this site, or run dig +short TXT _dmarc.example.com.