Skip to content

DMARC record generator

Choose a policy and a reporting address, then copy the exact TXT record to publish at _dmarc.yourdomain.

Policy for mail that fails DMARC
Advanced options

Your DMARC record

Type: TXT · Host/name: _dmarc (full name _dmarc.yourdomain.com)

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Published it? Check that it is live and valid. DNS changes can take a few minutes to an hour to appear.

A safe rollout

1. Publish p=none with a rua address. Nothing changes for your mail, but you start getting daily reports from Gmail, Yahoo, Microsoft and others.

2. Read the reports for two to four weeks. Every service that sends as you should pass SPF or DKIM with your domain aligned. Fix the ones that do not.

3. Move to p=quarantine, optionally with pct=25 and then higher, and finally to p=reject.

Since 2024, Gmail requires at least p=none from anyone sending around 5,000 or more messages a day to Gmail addresses, and Yahoo has a similar rule for bulk senders. Enforcement (quarantine or reject) is what actually stops spoofing.

Know the day it breaks

Records that are right today get edited, overwritten or dropped in a DNS move. SenderBeacon re-checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.

Start free trial

Questions

Where do I publish the DMARC record?

As a TXT record with the host/name _dmarc. Most DNS hosts add your domain automatically, so the full name becomes _dmarc.yourdomain.com.

Do I need a DMARC reporting service?

No. The reports are XML files sent by email. A free mailbox works, but a report reader makes them much easier to understand once you have more than a few senders.

Will p=reject block my own email?

Only mail that fails both SPF and DKIM alignment. That is why you start at p=none and check the reports first.