📋 DMARC Checker
Check DMARC (Domain-based Message Authentication, Reporting and Conformance) policy configuration for your domain.
What the check looks up
This tool queries live DNS. The domain you type is sent to SimpleMoney's
network-tools API, which reads the TXT record at the _dmarc label and
returns the policy it finds:
_dmarc.example.com TXT
v=DMARC1; p=reject; rua=mailto:dmarc@example.com; adkim=s; aspf=s; pct=100
v=DMARC1 must be first and p= second. The policy values are
none, quarantine and reject;
sp= sets a different policy for subdomains, and rua= is where
aggregate XML reports are sent.
Passing SPF or DKIM is not enough
DMARC asks a narrower question than either underlying check: does the domain that
passed also align with the From: address the reader sees? SPF
authenticates the envelope sender (the Return-Path), DKIM authenticates the
d= domain in the signature. A message can pass SPF outright and still fail
DMARC because the Return-Path is your bulk sender's domain, not yours.
- Relaxed alignment (the default) accepts an organisational-domain
match:
mail.example.comaligns withexample.com. - Strict alignment (
adkim=s,aspf=s) demands an exact match, so that same subdomain would fail.
p=none enforces nothing. It asks receivers to deliver
as they otherwise would and send you reports, which is the right place to start, but a
domain sitting at p=none is not protected from spoofing. Only
quarantine and reject ask receivers to act - and each
receiver still applies its own judgement.Frequently asked questions
Why does my mail fail DMARC when SPF passes?
Almost always alignment. SPF is checked against the envelope Return-Path, so a sending platform that uses its own bounce domain passes SPF on that domain while your From: domain stays unauthenticated. Fix it with a custom Return-Path on your domain, or by signing with DKIM using d=yourdomain.
Is p=none safe to leave in place?
It is safe in the sense that it changes nothing about delivery, which is also the problem. It collects the reports you need to find your legitimate senders, but until you move to quarantine or reject, nobody is asked to stop spoofed mail.
What does pct=20 do?
It applies the policy to roughly one message in five that fails, leaving the rest handled as if the policy were weaker. It is a ramp for moving to enforcement, not a permanent setting, and some receivers apply it inconsistently.