DMARC record generator
Choose a policy, add where reports should go, and get a valid DMARC TXT record to publish at _dmarc. Every option is explained in plain English, with a safe rollout plan from monitoring to reject.
- Free, no signup
- RFC 7489 compliant
- Rollout plan included
- Nothing stored
Build your DMARC policy
Everything updates as you go.
The domain in your From address. Used for the record name and to check report addresses.
What should receivers do with mail that fails DMARC?
pct has no effect while the policy is none. It matters once you move to quarantine or reject.
Where mailbox providers send daily XML summaries of who sent mail as your domain and whether it passed. Press Enter to add more than one.
Per-message failure reports. Few providers send them.
Your DMARC record
Add it as a TXT record at your DNS host.
- Type
- TXT
- Host
- _dmarc
Full name: _dmarc.yourcompany.com
Value
v=DMARC1; p=none
6 default tags left out
- sp=none · Subdomains without their own DMARC record follow p when sp is left out.
- pct=100 · The policy applies to 100% of failing mail by default.
- adkim=r · DKIM alignment is relaxed by default.
- aspf=r · SPF alignment is relaxed by default.
- fo=0 · By default a failure report is requested only when both SPF and DKIM fail to align.
- ri=86400 · Aggregate reports are requested once a day by default.
Checks
p=none only monitors. Receivers still deliver mail that fails DMARC, so it gives no protection against spoofing yet. Use it to collect reports, then move to quarantine (ramping pct up) and finally reject.
No rua address, so you won't receive aggregate reports. Without them you can't see which services send as your domain or whether they pass before you tighten the policy.
Recommended rollout
Tap a step to load its settings.
DMARC record generator in 3 steps
- 1
Pick a policy
Start with monitor only. The generator explains what quarantine and reject do to mail that fails.
- 2
Add report addresses
Aggregate reports show every service sending as your domain. Addresses are validated and mailto: is added for you.
- 3
Publish at _dmarc
Add one TXT record at _dmarc.yourdomain.com, then confirm it with our SPF, DKIM and DMARC checker.
A DMARC record you can publish with confidence
Every tag follows RFC 7489, and every warning tells you what it means for your mail.
Plain-English policies
See exactly what none, quarantine and reject do to failing mail before you choose.
Gradual rollout
A pct slider and a step-by-step plan take you from monitoring to reject without losing legitimate mail.
Report address checks
Invalid addresses are flagged, duplicates removed and mailto: added automatically.
External destination warning
Flags report addresses on another domain, with the exact authorisation record that domain needs.
Clean output
Default tags like pct=100 and adkim=r are left out, and you can see why each one was dropped.
Advanced tags explained
Subdomain policy, strict or relaxed alignment, failure options and report interval, each with an example.
How to roll out DMARC safely
DMARC (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do with mail that claims to be from your domain but fails authentication, and asks them to send you reports. It builds on SPF and DKIM: a message passes DMARC when SPF or DKIM passes for a domain that aligns with the one in the visible From address.
1. Set up SPF and DKIM first
Every service that sends as you needs SPF, DKIM or ideally both, on your domain. Build SPF with the SPF record generator and turn on DKIM in each provider's domain settings. DKIM matters most, because it survives forwarding and most email platforms sign with your domain once you add their records.
2. Publish p=none with reporting
Create a TXT record at _dmarc with a value like v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Nothing changes for your mail yet, but mailbox providers start sending daily aggregate reports. Use a dedicated mailbox or a DMARC reporting service, because reports arrive as compressed XML files and can be numerous.
3. Read the aggregate reports
Each report covers a time window and lists, per sending IP address, how many messages were seen, whether SPF and DKIM passed, which domains they checked, and what the receiver did. Look for:
- Your own services failing. A platform you use that fails alignment needs its DKIM or SPF records added before you enforce.
- Unknown sources. Servers you don't recognise sending as you are either a forgotten tool or someone spoofing your domain.
- Forwarding. Mail forwarded by mailing lists or other servers often fails SPF but can still pass on DKIM.
4. Move to quarantine, then reject
| Stage | Record | Move on when |
|---|---|---|
| Monitor | p=none | Every legitimate sender passes |
| Partial quarantine | p=quarantine; pct=25 | No unexpected failures for a week or two |
| Full quarantine | p=quarantine | Reports stay clean |
| Reject | p=reject | Keep monitoring for new senders |
With pct below 100, RFC 7489 says the mail that isn't sampled gets the next policy down, so p=reject; pct=50 quarantines the other half rather than delivering it. Timelines vary: a small company with a few services can move in weeks, while a large organisation may take months.
5. Keep reporting on
Leave rua in place after you reach reject. New tools get added, providers change their infrastructure, and reports are the only way to notice before mail starts failing. If reports go to an address on a different domain, that domain must publish an authorisation record at yourdomain.com._report._dmarc.theirdomain.com; reporting services do this for you.
When you're done, confirm everything with the SPF, DKIM and DMARC checker.
How do I create a DMARC record?
Choose a policy (start with p=none), add an email address for aggregate reports, and publish the result as a TXT record at _dmarc.yourdomain.com. The generator above builds the value, such as v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com, as you choose options.
Where do I add the DMARC record?
At your DNS host. Create a TXT record with the host or name set to _dmarc. Some DNS hosts add your domain automatically; others want the full name, _dmarc.yourdomain.com. Only one DMARC record is allowed per domain.
What's the difference between p=none, p=quarantine and p=reject?
p=none only monitors: failing mail is delivered as usual and you receive reports. p=quarantine asks receivers to treat failing mail as suspicious, usually by putting it in spam. p=reject asks them to refuse it. Only quarantine and reject protect you from spoofing.
What does pct mean in DMARC?
pct is the percentage of failing mail the policy applies to, from 0 to 100 (the default). Under RFC 7489, mail that isn't sampled gets the next policy down: reject becomes quarantine, and quarantine becomes none. It lets you tighten the policy gradually.
What are rua and ruf?
rua is where mailbox providers send aggregate reports: daily XML summaries of the servers that sent mail as your domain and whether SPF, DKIM and DMARC passed. ruf is for forensic reports about individual failing messages, which few providers send.
Can I send DMARC reports to another domain?
Yes, but the receiving domain must agree to accept them by publishing a TXT record v=DMARC1 at yourdomain.com._report._dmarc.theirdomain.com (RFC 7489, section 7.1). DMARC reporting services set this up for you. Without it, providers won't send reports there.
How long should I stay on p=none?
Long enough to see every service that sends as you in the reports, usually two to four weeks of normal mail. Once legitimate senders pass SPF or DKIM with alignment, move to quarantine with a low pct, raise it to 100, then move to reject.
Do I need SPF and DKIM before DMARC?
Yes. DMARC passes only when SPF or DKIM passes for a domain aligned with the From address, so set up at least one of them, ideally both, for every sender first. Use our SPF record generator to build SPF.
Keep going
Your domain is protected. Now put it to work.
Atlis tracks what each user does after signup and sends lifecycle emails automatically: onboarding nudges, re-engagement, churn recovery and failed-payment recovery.
Free plan · No credit card · 10-minute setup