DMARC Record Generator - Build a Valid DMARC TXT Record with Warnings
DMARC Record Generator
Tell receivers how to treat mail that fails SPF and DKIM, and where to send reports
A Valid Record
Pick a policy and reporting addresses and the tool writes a correct v=DMARC1 record with only the tags you need.
A Safe Roll-Out
Start with p=none to watch reports, then quarantine and reject, using testing mode (or the legacy percentage) to phase it in.
Plain-Language Warnings
Flags monitoring-only policies, missing report addresses, external report domains and settings that do nothing.
Full Privacy
Everything is built in your browser.
What DMARC Does
DMARC builds on SPF and DKIM. It tells receiving mail servers what to do with messages that fail both checks in a way that lines up with the visible From domain: nothing (none), treat as suspicious (quarantine) or refuse (reject). It also asks receivers to send you reports, so you can see who is sending mail as your domain, legitimate or not. The record is a TXT record published at _dmarc.yourdomain.
The safe way in is gradual: publish p=none with a rua address, read the reports for a few weeks and fix any legitimate senders that fail, then move to quarantine (t=y asks receivers to hold back while you test, and the older pct tag can start with a fraction of mail) and finally reject. Only the p tag is required, and the current standard, RFC 9989, also adds np for subdomains that do not exist. Relaxed alignment lets subdomains match the main domain and suits most senders; strict alignment demands an exact match.
Key Takeaways
- Publish at _dmarc: The host name is _dmarc.yourdomain; the tool shows the exact line.
- Needs SPF or DKIM first: DMARC only passes when SPF or DKIM passes and aligns, so set those up first.
- Related tools: See also the SPF Record Generator and the Email Deliverability Checker.