HomeBlogWhat Is a DMARC Record? A Plain-English Guide for 2026
Security 9 min read

What Is a DMARC Record? A Plain-English Guide for 2026

DMARC stops spammers from impersonating your domain. This guide explains exactly what a DMARC record is, what each tag does, how to analyze your policy, and how to check any domain's DMARC record in seconds.

goodboycoder
goodboycoderFounder
Founder of FreeMailTools
Published 2026-08-10

What Is a DMARC Record?

DMARC stands for Domain-based Message Authentication, Reporting & Conformance. It's a DNS TXT record that tells the world's mail servers what to do with emails that fail to authenticate as coming from your domain.

Without DMARC, anyone can send email that appears to be from your domain. With DMARC, you control whether those messages get delivered, sent to spam, or rejected outright.


Why DMARC Exists

Email was designed in the 1970s. There was no mechanism to verify that the "From" address in an email was legitimate. DMARC, introduced as an industry standard in 2012 and made an RFC standard in 2015 (RFC 7489), fills this gap by building on two earlier authentication standards:

  • SPF (Sender Policy Framework) — Lists the mail servers authorized to send email for your domain
  • DKIM (DomainKeys Identified Mail) — Cryptographically signs each outgoing message

DMARC adds a policy layer on top: it tells receiving mail servers what to do when SPF or DKIM checks fail, and provides a reporting mechanism so you can see who is sending email from your domain.


Anatomy of a DMARC Record

A DMARC record is published as a DNS TXT record at the subdomain _dmarc.yourdomain.com. Here's a real example:

text

Tag breakdown

TagRequiredExampleMeaning
vYesDMARC1DMARC version (always DMARC1)
pYesnone, quarantine, rejectPolicy for failing messages
pctNo100% of messages the policy applies to
ruaNomailto:reports@you.comWhere aggregate reports go
rufNomailto:forensic@you.comWhere forensic reports go
adkimNor or sDKIM alignment: relaxed or strict
aspfNor or sSPF alignment: relaxed or strict
spNonone, quarantine, rejectPolicy for subdomains
foNo0, 1, d, sFailure reporting options

DMARC Policies Explained

The p= tag is the most important part of your DMARC record. There are three values:

p=none

Monitor mode. Failing messages are delivered normally. You receive reports so you can see what's happening without breaking email. Start here when implementing DMARC.

p=quarantine

Spam mode. Failing messages are sent to the recipient's spam/junk folder. This blocks most phishing attempts but doesn't outright reject messages.

p=reject

Full protection. Failing messages are rejected at the MTA level — they never reach any inbox. This is the goal of DMARC deployment. Google and Yahoo require at least p=quarantine as of February 2024 for bulk senders.


How to Check a Domain's DMARC Record

Use our free DMARC Checker tool. Enter any domain and get:

  • The complete raw DMARC record
  • Policy level (none / quarantine / reject)
  • Percentage coverage (pct value)
  • Reporting addresses
  • Alignment settings
  • Human-readable analysis of what the policy means

You can also run it manually with dig:

bash

Or with nslookup:

text

DMARC Alignment: Relaxed vs. Strict

Alignment determines how the domain in the From header must match the domain used by SPF and DKIM.

  • Relaxed (r): The organizational domain must match. mail.example.com passes for example.com.
  • Strict (s): An exact match is required. mail.example.com fails for example.com.

Most organizations use relaxed alignment (adkim=r; aspf=r) to avoid breaking legitimate mail from subdomains.


DMARC Reports

When you add a rua address to your DMARC record, major mail providers (Google, Microsoft, Yahoo, Apple Mail) send you daily XML reports showing:

  • Which IP addresses sent email claiming to be from your domain
  • Whether those messages passed SPF and DKIM
  • What policy was applied

These reports are invaluable for identifying unauthorized senders, shadow IT, misconfigured mailing lists, and phishing campaigns.

Use our DMARC Analyzer to parse and visualize these XML reports in a human-readable format.


Common DMARC Mistakes

  1. Starting at p=reject immediately — Break legitimate mail flows. Always start at p=none, analyze reports, then move to quarantine, then reject.

  2. No rua reporting address — Without reports, you're flying blind. Always set up aggregate reporting.

  3. Forgetting subdomains — Add sp= to specify policy for subdomains if they're not covered by their own DMARC records.

  4. 100% pct on quarantine before validation — Set pct=10 or pct=25 to gradually roll out stricter policies while monitoring impact.


goodboycoder

Written by goodboycoder

Founder of FreeMailTools

goodboycoder is the Founder & Lead Developer of FreeMailTools. Building 100% free, developer-first tools for email authentication (SPF, DKIM, DMARC), DNS inspection, disposable temporary inboxes, and deliverability optimization.

Test Your Domain Setup Live

Run real-time SPF, DKIM, DMARC, and DNS lookups on your own domain with 100% free developer tools.

Explore Tools

Related Guides & Comparisons

Tools Comparison

Top 10 Best Free Email Tools for Developers & Marketers (2026)

A hands-on roundup of the best free tools for email validation, DNS authentication, deliverability testing, spam analysis, and temporary inboxes — with real links.

Security

SPF vs DKIM vs DMARC: What Each Does and Why You Need All Three

A technical breakdown of the three email authentication standards — SPF, DKIM, and DMARC — what each protects against, how they interact, and how to set them up correctly.