DMARC record checker
Look up a domain's DMARC record and see its policy, where reports go, and what to change next.
Build a DMARC record
Pick a policy and a reporting address, then copy the record into your DNS.
_dmarcv=DMARC1; p=none;Add a reporting address. Without it, nobody receives reports about mail that fails.
What this checks
That there's exactly one DMARC record at _dmarc.yourdomain.com, that its policy is valid, whether reports are being collected, and how strictly SPF and DKIM have to align with your From address.
DMARC and toSend
Email sent through toSend passes DMARC through DKIM: it's signed with your own domain. SPF uses send.yourdomain.com, which aligns under the default relaxed setting. If you set aspf=s, SPF stops aligning for toSend mail, but DKIM still passes, so DMARC still passes. Our DMARC guide walks through a safe rollout.
Questions
Which policy should I start with?
Start with p=none and a rua address so you receive reports without affecting delivery. Once the reports show your real senders passing, move to p=quarantine, then p=reject.
What is the rua tag?
The address where mailbox providers send daily aggregate reports about mail that claimed to come from your domain. Without it you can't see what's passing or failing.
Do I need DMARC if I only send a little email?
Yes. Gmail and Yahoo require a DMARC record from bulk senders, and it stops other people sending email that pretends to be from your domain.
Ready to send? Your first 10,000 are on us.
Every feature included. No tiers. For one website, one app, or fifty client sites.