VMHeaven

Free tool

DMARC record checker

Check a DMARC record tag by tag: the policy and what receivers do with it, the subdomain policy, pct, and whether the report addresses accept the reports.

Check a DMARC record

Try:

Read from DNS by our validating resolver in Amsterdam — this check never connects to the domain’s mail servers.

The tags

TagValuesMeaning
vDMARC1Version; must come first
pnone | quarantine | rejectWhat receivers do with failing mail — required
spnone | quarantine | rejectThe same for subdomains; p= when left out
pct0–100Share of failing mail the policy applies to; 100 when left out
ruamailto:…Where daily aggregate reports go
rufmailto:…Where reports on single failing messages go; rarely sent
adkim, aspfr | sRelaxed or strict alignment for DKIM and SPF; relaxed when left out
fo0 | 1 | d | sWhen failure reports are wanted

Moving to reject without losing mail

  1. 1Monitor

    Publish p=none with a report address and leave it for two to four weeks. The aggregate reports list every server that sent mail as your domain — your own, your providers’, and anyone spoofing you.

  2. 2Fix your own sources

    Every legitimate source must pass SPF or DKIM for your domain: add missing includes to SPF, turn on DKIM signing with your domain at each service that sends for you.

  3. 3Quarantine, then reject

    Move to p=quarantine, if you like with pct=25 first, and raise it while the reports stay clean. Then switch to p=reject.

DNS · TXT records
; step 1: monitoring
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc@example.com"

; step 3: enforcing, subdomains included
_dmarc.example.com.  TXT  "v=DMARC1; p=reject; rua=mailto:dmarc@example.com"

Reports to another domain

When rua points to an address at another domain — a report service, or your company’s main domain — that domain has to agree to receive them, or receivers do not send the reports. It does so with one record that names your domain:

DNS · TXT record at the receiving domain
example.com._report._dmarc.reports.example.net.  TXT  "v=DMARC1"

Report services publish a wildcard record for this. The checker above asks for the record of every outside address in rua and says which ones are missing it.

Frequently asked

What does DMARC do?

It tells receiving mail servers what to do with a message whose visible From domain is not confirmed by SPF or DKIM — deliver it anyway (p=none), put it in spam (quarantine) or refuse it (reject) — and asks them to send you reports. A message passes DMARC when SPF or DKIM passes for a domain that matches the From domain.

p=none, quarantine or reject — which should I use?

Start with p=none and a rua= address, and read the reports for a few weeks: they show every server that sends mail as your domain. Once all of your own mail passes, move to quarantine — pct= lets you apply it to part of the failing mail first — and then to reject. p=none on its own protects nothing.

What are rua and ruf?

rua is where receivers send aggregate reports, usually once a day: which addresses sent mail as your domain, how much, and whether SPF and DKIM passed. ruf asks for failure reports on single messages, which few large providers send. Reports for another domain's address are only sent if that domain publishes an authorisation record, which this checker tests.

What is DMARC alignment?

The rule that the domain SPF or DKIM vouches for must match the From domain. Relaxed alignment, the default, accepts a subdomain (mail.example.com for example.com); strict alignment (adkim=s, aspf=s) requires the exact name. Mail services that sign with their own domain fail alignment until you set them up to sign as yours.

Why does my subdomain show the main domain's record?

A subdomain without a DMARC record of its own falls under the record of its organisational domain — the name you registered — with that record's sp= policy, or p= when there is no sp=.

More free tools

All tools