DNS Tool • RFC 7489 Compliance • Anti-Spoofing

Free DMARC Record Generator & Policy Wizard

Create an RFC 7489-compliant DMARC policy record in seconds. Protect your domain against impersonation, configure aggregate reporting (RUA), and meet Google & Yahoo 2024 sender mandates.

Quick Answer • Standard DMARC Record Format

A standard DMARC policy record is published as a DNS TXT record under the host _dmarc.yourdomain.com. The recommended anti-spoofing policy is: v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com; pct=100; aspf=r; adkim=r;

Interactive DMARC Policy Wizard

Configure your domain's authentication policy and reporting parameters below.

Receives daily XML aggregate reports of all senders using your domain.
Receives instant forensic copies of individual spoofed messages.
Generated Ready-to-Deploy DMARC DNS Record
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; pct=100; aspf=r; adkim=r;
DNS Record Type: TXT • Host / Name: _dmarcValidate in Live DMARC Checker →

1. The Fundamental Mechanics of DMARC (RFC 7489)

Domain-based Message Authentication, Reporting, and Conformance (DMARC), standardized in RFC 7489, represents the highest level of policy governance in email infrastructure. While SPF authenticates the technical envelope sender (Return-Path) and DKIM authenticates message body integrity via digital signatures, neither protocol guarantees that the visual header shown to human recipients (the RFC 5322 From: address) is legitimate.

Without DMARC, a cybercriminal can set up an authentic server with a passing SPF record for evil-attacker.com, while setting the visual header to support@yourbank.com. Recipient mail filters inspecting only SPF will see an authentication pass, allowing the fraudulent email into the inbox. DMARC solves this vulnerability through Identifier Alignment.

2. The 3-Phase DMARC Rollout Lifecycle

Enforcing p=reject overnight on a domain with active business traffic can result in legitimate corporate emails (such as transactional receipts or CRM notifications) being accidentally blocked. Industry best practices dictate a staged 3-phase rollout:

Phase 1: Discovery & Audit (p=none)

Deploy v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; for 30 to 60 days. In this monitoring mode, no email delivery is impacted. Analyze the incoming daily XML aggregate telemetry to identify all legitimate sending services (e.g. Google Workspace, SendGrid, Zendesk, Salesforce) and fix any misconfigured SPF includes or DKIM selectors.

Phase 2: Quarantine & Staged Rollout (p=quarantine)

Update the policy to p=quarantine; pct=25; and gradually ramp up to pct=100. Unauthenticated messages are diverted away from the inbox into the recipient's Spam/Junk folder. Monitor support queues for any false positives.

Phase 3: Total Anti-Spoofing Immunity (p=reject; pct=100)

Publish v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourdomain.com; pct=100; aspf=r; adkim=r;. Unauthorized emails spoofing your domain are permanently rejected at the SMTP boundary before reaching customer mailboxes. This also unlocks eligibility for BIMI verified inbox logos.

3. Identifier Alignment: Relaxed (r) vs. Strict (s) Modes

DMARC evaluates alignment across two distinct cryptographic vectors:

SPF Alignment (aspf=)

Under Relaxed (aspf=r), a Return-Path of bounces.domain.com aligns with a From: domain.com. Under Strict (aspf=s), the hostnames must match exactly.

DKIM Alignment (adkim=)

Under Relaxed (adkim=r), a signature with d=corp.domain.com aligns with From: domain.com. Under Strict (adkim=s), the signing domain d= must match the From header identically.

4. Frequently Asked Questions (DMARC Policy FAQ)

What is DMARC and why is it mandatory in 2026?

DMARC (Domain-based Message Authentication, Reporting, and Conformance, RFC 7489) is an email security protocol that verifies the domain in the visual From: header matches authenticated SPF or DKIM domains. Google and Yahoo mandate DMARC records for all bulk senders delivering over 5,000 messages per day to prevent spam, phishing, and domain impersonation.

What is the difference between p=none, p=quarantine, and p=reject?

p=none is a monitoring-only mode where failing emails are still delivered to inboxes while sending telemetry to your rua= address. p=quarantine instructs receiving servers to route failing emails directly into the recipient's Spam/Junk folder. p=reject is the strongest anti-spoofing policy, completely blocking unauthenticated emails at the SMTP gateway.

What is DMARC Identifier Alignment?

Identifier Alignment requires that the domain shown to human users in the From: header matches either the envelope Return-Path domain (for SPF alignment) or the d= domain in the cryptographic signature (for DKIM alignment). Under relaxed alignment (r), subdomains match their root; under strict alignment (s), the domains must match exactly.

What is the difference between RUA and RUF reports?

RUA (Reporting URI Aggregate) delivers daily XML summaries containing sender IP addresses, message volumes, and SPF/DKIM pass/fail statistics. RUF (Reporting URI Forensic / Failure) sends instant real-time redactions of individual unauthenticated messages for threat analysis.

Where should a DMARC record be published in DNS?

A DMARC record must always be published as a TXT record under the subdomain _dmarc (e.g. _dmarc.yourdomain.com). Never publish DMARC at the root @ host.

Does DMARC protect inbound or outbound email?

Publishing a DMARC record protects your outbound email reputation and prevents external attackers from sending fraudulent spoofed emails using your brand name to customers, partners, and employees.

What is the difference between DMARC p=quarantine and p=reject?

p=quarantine instructs receiving mail servers to deliver unaligned messages to the recipient's spam or junk folder rather than the inbox. p=reject instructs servers to silently discard the message entirely — it never reaches the recipient. For maximum anti-spoofing protection, p=reject is the recommended final policy.

What are DMARC aggregate reports (rua=) and how do I use them?

The rua= tag specifies an email address (e.g. rua=mailto:dmarc-reports@yourdomain.com) that receives XML aggregate reports from receiving mail servers. These daily reports show which sources are sending email claiming your domain, whether SPF and DKIM pass or fail, and how many messages each source sends. They are essential for monitoring before enforcing p=reject.

What is the DMARC pct= tag and how should I use it for staged rollout?

The pct= tag specifies the percentage of messages the DMARC policy is applied to (1–100). Setting pct=25 means only 25% of failing messages are affected by the policy, allowing gradual enforcement. Start with pct=10 at p=quarantine, monitor reports for 2–4 weeks, then increase to pct=100 before moving to p=reject.

What is DMARC alignment and why does it matter?

DMARC alignment means the domain in the message's visible From: header must match (align with) the domain used for SPF authentication (the Return-Path/envelope sender) or the DKIM d= tag. Without alignment, passing SPF or DKIM on a different domain does not satisfy DMARC — this prevents indirect spoofing via third-party mail infrastructure.

What is the DMARC sp= tag for subdomain policy?

The sp= tag sets a separate DMARC policy for all subdomains of your domain (e.g. sp=reject means mail.yourdomain.com, alerts.yourdomain.com, etc. are all covered). Without sp=, subdomains inherit the root domain's p= policy. sp=reject is recommended for high-security brands to prevent attackers from creating authenticated spoofed subdomains.

Can I have a DMARC record without SPF or DKIM?

You can publish a DMARC record, but it will have no enforcement effect unless at least one of SPF or DKIM is also configured and achieves identifier alignment. DMARC evaluates both and passes if either one aligns. Both failing simultaneously triggers the DMARC policy action.

How long should I monitor with p=none before moving to p=quarantine?

The recommended monitoring period with p=none is 30–90 days. During this time, analyze daily DMARC aggregate reports to identify all legitimate sending sources. Once you have confirmed all sources pass SPF or DKIM alignment, move to p=quarantine at pct=10, then increase gradually over 2–4 weeks to pct=100 before enforcing p=reject.

What is DMARC forensic reporting (ruf=) and is it safe to enable?

The ruf= tag requests forensic reports — individual copies of failing messages, including headers and sometimes body content. These arrive in real time when a DMARC failure occurs. Exercise caution: forensic reports may contain sensitive user data. Many major inbox providers (Gmail, Outlook) no longer send ruf= reports due to privacy concerns. Aggregate rua= reports are sufficient for most use cases.