🛡️ DMARC Record Builder
Configure your DMARC policy to generate a TXT record. Publish it at _dmarc.yourdomain.com.
How your choices become a record
The builder runs entirely in your browser and queries no DNS. It assembles the tags
in a fixed order, adds mailto: in front of any address you type, and
leaves out pct when it is 100 and rua or ruf
when the box is empty. Choosing quarantine at 25 per cent with relaxed alignment
produces:
Host: _dmarc.yourdomain.com
Value: v=DMARC1; p=quarantine; pct=25;
rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r;
A percentage outside 1-100 is rejected before anything is built. Publish the result
as one TXT record at _dmarc on the domain that appears in your
From: header.
Choosing the tags
p=none | Reports only. Nothing is quarantined or rejected, so spoofing is unaffected. Start here to learn who sends as you. |
p=quarantine | Asks receivers to treat failures as suspicious, usually the spam folder. |
p=reject | Asks receivers to refuse failures at SMTP time. |
adkim / aspf | Relaxed lets a subdomain satisfy the parent; strict demands the exact domain. |
DMARC does not simply relay the SPF or DKIM verdict. It passes only when one of those checks passes and the domain it authenticated lines up with the visible From: address, which is why a message from a bulk sender can pass SPF and still fail here.
p=reject can cause receivers to
refuse your own mail; no policy setting can promise a particular delivery outcome.Frequently asked questions
What should my first DMARC record be?
Policy none with an rua address, and nothing else: v=DMARC1; p=none;
rua=mailto:you@example.com;. That produces daily aggregate reports without
touching delivery, which is what you need before tightening anything.
Do I need ruf as well as rua?
No, and most people skip it. Forensic reports contain message content, so many providers never send them and some cannot for privacy reasons. Aggregate reports carry the counts and source IPs you actually work from.
Where do I put the record for a subdomain?
At _dmarc.sub.example.com if you want a policy specific to it.
Otherwise subdomains inherit the parent's policy, or the sp= tag on the
parent if one is set - this builder writes the parent policy only.