Skip to content

DMARC record checker

Enter a domain to read its DMARC record at _dmarc.<domain>, check it is valid, and see what the policy actually does to spoofed mail.

Reading a DMARC record

p= is the policy. none only monitors, quarantine sends failing mail to spam, and reject blocks it. rua= is where daily aggregate reports go. pct= applies the policy to only part of failing mail. sp= sets a separate policy for subdomains.

A sensible path: start at p=none with a rua address, read the reports until every real sender passes, then move to p=quarantine and finally p=reject.

Monitor it instead of checking by hand

Get an email if your DMARC record disappears or changes. Plans from $9/month after a 14-day free trial. No card to start.

Questions

Is p=none enough for Gmail and Yahoo?

For the 2024 bulk-sender rules, yes: they require a DMARC record and accept p=none. It does not stop anyone from spoofing your domain, though.

Why does my DMARC record not work?

The usual causes: it was published at the root instead of _dmarc.yourdomain, there are two DMARC records, or the p= tag is missing or misspelled. This checker flags all three.

More free checks

Check a provider setup