dmarcula

Tools

DMARC record generator.

Build a valid DMARC record tag by tag, with each option explained, then copy it into DNS.

Typing stays in your browser. Load current record does one DNS lookup through dmarcula to read your live record so you can compare. Nothing is stored.

Your DMARC record

Add this as a TXT record at _dmarc.yourdomain.com

Policy

What receivers do with mail that fails, and how much of it.

Start at none, climb to reject once you trust your reports.

Policy for existing subdomains. Omit to use the main policy.

Policy for subdomains that don't exist in DNS. np=reject shuts the door on made-up ones. Newer tag; omit to inherit sp/p.

Soft-launch a policy: receivers apply the next-lower policy and only report, so p=reject behaves like quarantine while you watch. The modern replacement for the removed pct tag. Omit once a rung runs clean.

Reporting

Where the daily summaries and failure reports are sent.

Daily XML summaries of who sends as you. Comma-separate several. The whole point of DMARC.

Per-message failure samples. Rare, may contain content. Leave blank unless needed.

Failure reporting options fo

When receivers should send a forensic report. Only matters if you set a ruf address.

The d and s add-ons report when DKIM or SPF fails on its own, regardless of alignment. They are independent of the choice above.

Tip: while you roll out (before p=reject), fo=1 gives the fullest view of what's failing. It only does anything if you set a ruf address above, and not every receiver sends these reports.

Seconds between aggregate reports. Most receivers only honour 86400 (a day). Omitted when 86400.

Alignment

How closely the authenticated domain must match your From address.

Relaxed lets mail.you.com align with you.com. Omitted when relaxed.

Same idea as DKIM alignment, for the SPF domain. Omitted when relaxed.

Using your record

Publish it. Add the generated string as a TXT record at _dmarc.yourdomain.com in your DNS provider. It can take up to a day to propagate; the DMARC checker confirms once it is live.

Start safe. Begin at p=none with an rua address. You collect reports on who sends as you without touching delivery, which is exactly what you want before tightening anything.

Climb when ready. Once your reports show only senders you recognise, move to quarantine and then reject. The enforcement journey walks through doing that without blocking real mail, and DMARC in plain English covers the fundamentals.

Frequently asked questions

How do I create a DMARC record?
Choose your policy, add the address that should receive aggregate reports, and adjust alignment if you need to. The generator assembles a valid record live; copy it and publish it as a TXT record at _dmarc.yourdomain.com.
What is a good DMARC record to start with?
Start with p=none and an rua address so you can see who sends as you without affecting delivery. Once your reports look clean, raise the policy to quarantine and then reject.
Where do I publish the DMARC record?
Add it as a TXT record at the host _dmarc.yourdomain.com in your DNS provider. The value is the full string the generator produces, beginning with v=DMARC1.
What is the difference between rua and ruf?
rua receives daily aggregate XML summaries of all mail claiming to be from your domain, which is the data DMARC is built on. ruf receives individual failure samples, is far less widely supported, and can contain message content.
Do I need both SPF and DKIM for DMARC?
DMARC passes when either SPF or DKIM passes and aligns with your From domain, so you need at least one. Setting up both is recommended so a single failure, such as forwarding breaking SPF, does not cause a DMARC failure.

This check is a snapshot. dmarcula watches your domain around the clock, reads the DMARC reports for you, and emails you when something changes. Free, no credit card.