DMARC record checker

Updated

Enter the domain that appears in your From address. The checker reads the TXT record at _dmarc. plus that domain.

Looks up public DNS only. Nothing you enter is stored.

What the checker tests

  • A single record starting with v=DMARC1
  • The p= policy: none (monitor), quarantine, or reject
  • pct= rollout percentage and the subdomain policy sp=
  • Whether rua= is set, and whether reports sent to another domain are authorised by that domain
  • Whether alignment is relaxed (default) or strict for DKIM (adkim) and SPF (aspf)

It reads the record. It cannot tell you whether your real mail passes DMARC. For that, read the aggregate reports sent to your rua address, or check the Authentication-Results header on a test message.

A sensible progression

  1. v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
  2. Review reports. Fix or authenticate each legitimate sender.
  3. p=quarantine; pct=25, then raise pct to 100.
  4. p=reject once reports are clean.

Mistakes the checker catches

  • Two DMARC records, which receivers discard
  • A missing p= tag
  • Reports addressed to an external domain that never published the authorisation record
  • Staying on p=none indefinitely

Context: SPF, DKIM and DMARC explained.

Frequently asked questions

Should I start with p=reject?
No. Start with p=none and a rua address, read the aggregate reports for a few weeks, authenticate every legitimate sender, then move to quarantine and reject.
What does pct do?
pct sets the percentage of failing mail the policy applies to, which lets you roll out enforcement gradually. Leaving it out means 100.

Need reliable email delivery? Try Inboxili

Create a workspace, verify a domain, and make your first API call.

Related