EML

DMARC Record Generator

Choose a policy and where reports should go, and get a DMARC record ready to publish.

PUBLISH AS A TXT RECORD NAMED _dmarc

            

How it works

A DMARC record is a TXT record at _dmarc.yourdomain.com. This generator only writes tags that differ from the defaults, so the record stays short, and it checks the report addresses as you type.

The safe order for rolling DMARC out is gradual:

StageRecordWhy
1. Watchp=none with ruaCollect reports, change nothing.
2. Soft enforcep=quarantine, pct rising to 100Failing mail goes to spam.
3. Enforcep=rejectFailing mail is refused.

Before you enforce, make sure SPF and DKIM are set up and passing for every service that sends as your domain. Check the live record afterwards with the DMARC Record Checker.

Frequently asked

What should my first DMARC record be?

v=DMARC1; p=none; rua=mailto:an-address-you-read. It changes nothing about delivery and starts sending you reports that show who is sending as your domain.

Do I need a special mailbox for reports?

Reports are XML files sent daily by each large receiver and can be numerous. A dedicated address, or a free DMARC report service, keeps your normal inbox clear.

Can the report address be on another domain?

Yes, but that other domain must publish a TXT record named yourdomain._report._dmarc.otherdomain with the value v=DMARC1, otherwise receivers will not send the reports there. Report services handle this for you.

What does pct do?

It applies the policy to only that percentage of failing mail, so you can ramp up gradually. It has no effect when the policy is none.

Strict or relaxed alignment?

Relaxed lets mail.example.com match example.com and is right for most domains. Choose strict only if you need the domains to match exactly.