What Is a DMARC Record?
DMARC stands for Domain-based Message Authentication, Reporting & Conformance. It's a DNS TXT record that tells the world's mail servers what to do with emails that fail to authenticate as coming from your domain.
Without DMARC, anyone can send email that appears to be from your domain. With DMARC, you control whether those messages get delivered, sent to spam, or rejected outright.
Why DMARC Exists
Email was designed in the 1970s. There was no mechanism to verify that the "From" address in an email was legitimate. DMARC, introduced as an industry standard in 2012 and made an RFC standard in 2015 (RFC 7489), fills this gap by building on two earlier authentication standards:
- SPF (Sender Policy Framework) — Lists the mail servers authorized to send email for your domain
- DKIM (DomainKeys Identified Mail) — Cryptographically signs each outgoing message
DMARC adds a policy layer on top: it tells receiving mail servers what to do when SPF or DKIM checks fail, and provides a reporting mechanism so you can see who is sending email from your domain.
Anatomy of a DMARC Record
A DMARC record is published as a DNS TXT record at the subdomain _dmarc.yourdomain.com. Here's a real example:
Tag breakdown
| Tag | Required | Example | Meaning |
|---|---|---|---|
v | Yes | DMARC1 | DMARC version (always DMARC1) |
p | Yes | none, quarantine, reject | Policy for failing messages |
pct | No | 100 | % of messages the policy applies to |
rua | No | mailto:reports@you.com | Where aggregate reports go |
ruf | No | mailto:forensic@you.com | Where forensic reports go |
adkim | No | r or s | DKIM alignment: relaxed or strict |
aspf | No | r or s | SPF alignment: relaxed or strict |
sp | No | none, quarantine, reject | Policy for subdomains |
fo | No | 0, 1, d, s | Failure reporting options |
DMARC Policies Explained
The p= tag is the most important part of your DMARC record. There are three values:
p=none
Monitor mode. Failing messages are delivered normally. You receive reports so you can see what's happening without breaking email. Start here when implementing DMARC.
p=quarantine
Spam mode. Failing messages are sent to the recipient's spam/junk folder. This blocks most phishing attempts but doesn't outright reject messages.
p=reject
Full protection. Failing messages are rejected at the MTA level — they never reach any inbox. This is the goal of DMARC deployment. Google and Yahoo require at least p=quarantine as of February 2024 for bulk senders.
How to Check a Domain's DMARC Record
Use our free DMARC Checker tool. Enter any domain and get:
- The complete raw DMARC record
- Policy level (none / quarantine / reject)
- Percentage coverage (
pctvalue) - Reporting addresses
- Alignment settings
- Human-readable analysis of what the policy means
You can also run it manually with dig:
Or with nslookup:
DMARC Alignment: Relaxed vs. Strict
Alignment determines how the domain in the From header must match the domain used by SPF and DKIM.
- Relaxed (
r): The organizational domain must match.mail.example.compasses forexample.com. - Strict (
s): An exact match is required.mail.example.comfails forexample.com.
Most organizations use relaxed alignment (adkim=r; aspf=r) to avoid breaking legitimate mail from subdomains.
DMARC Reports
When you add a rua address to your DMARC record, major mail providers (Google, Microsoft, Yahoo, Apple Mail) send you daily XML reports showing:
- Which IP addresses sent email claiming to be from your domain
- Whether those messages passed SPF and DKIM
- What policy was applied
These reports are invaluable for identifying unauthorized senders, shadow IT, misconfigured mailing lists, and phishing campaigns.
Use our DMARC Analyzer to parse and visualize these XML reports in a human-readable format.
Common DMARC Mistakes
-
Starting at
p=rejectimmediately — Break legitimate mail flows. Always start atp=none, analyze reports, then move toquarantine, thenreject. -
No
ruareporting address — Without reports, you're flying blind. Always set up aggregate reporting. -
Forgetting subdomains — Add
sp=to specify policy for subdomains if they're not covered by their own DMARC records. -
100% pct on quarantine before validation — Set
pct=10orpct=25to gradually roll out stricter policies while monitoring impact.
Related Tools
- DMARC Checker — Look up and analyze any domain's DMARC record
- DMARC Generator — Build a DMARC record with the correct syntax
- DMARC Analyzer — Parse and analyze DMARC XML reports
- SPF Checker — Validate your SPF record
- DKIM Checker — Check DKIM signatures
