What goes into a DMARC record
DMARC is a TXT record at _dmarc.<domain>. p is the policy for mail that fails: none (only report), quarantine (treat as suspicious, usually the spam folder) or reject. sp sets a different policy for subdomains. rua is where aggregate reports go, one XML summary per receiver per day; ruf asks for per-message failure reports, which few receivers send. pct applies the policy to a share of failing mail. adkim and aspf choose relaxed (organizational domain) or strict (exact domain) alignment, and fo selects when failure reports are generated.
The generator leaves out tags that are at their default value, so a typical record stays short: v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com.
Roll it out in stages: none, quarantine, reject
Start with p=none and a rua address. Nothing changes for your mail, and within days the reports show every system that sends with your domain: the newsletter tool, the invoicing system, the forgotten web form. Fix SPF and DKIM for each legitimate source until the reports show them passing with alignment.
Then move to p=quarantine, optionally with pct=25 and rising, and watch the reports again. When legitimate mail no longer fails, publish p=reject. Rushing to reject without reading reports is the usual way to lose real mail.
Reports sent to another domain
If the rua or ruf address is on a different domain than the one the record is for, that other domain has to agree: it publishes a TXT record v=DMARC1 at <your domain>._report._dmarc.<their domain>. Reporting services set this up for their customers. The generator shows the exact host name when it applies.