All tools
DELIVERABILITY TOOL / 06

DMARC record
builder

Build a current DMARC policy, understand exactly what it asks receivers to do, and catch risky rollout choices before changing DNS.

  • RFC 9989 tags
  • Rollout readiness
  • No domain data sent
Configure policy
Advanced controls +
GENERATED DNS RECORD

Ready to copy—not yet ready to publish.

RFC 9989
TYPETXT
HOST / NAME_dmarc.example.com
VALUE / CONTENT46 characters
v=DMARC1; p=none; rua=mailto:[email protected]
_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]"
FAILURE POLICYnone

Monitor authentication results; no quarantine or rejection is requested.

IDENTIFIER ALIGNMENTRelaxed

DKIM or SPF may align through the same organizational domain.

REPORTING1

aggregate report destination(s) requested

PRE-PUBLISH AUDIT

Record syntax looks coherent.

No syntax issues found

Publication safety still depends on complete SPF and DKIM coverage for your real sending sources.

ENFORCEMENT READINESS

0/5 checks complete.

SAFER ROLLOUT

Move policy only after the evidence moves.

  1. 01
    Monitor

    Publish p=none with aggregate reporting and inventory every authorized source found in reports.

  2. 02
    Align

    Make at least one authenticated identifier align for every legitimate stream—preferably both DKIM and SPF.

  3. 03
    Test

    Use p=quarantine with t=y, then remove test mode when reports show expected mail remains healthy.

  4. 04
    Enforce

    Move through quarantine to reject only when aggregate evidence and operational ownership support it.

A pass needs one aligned authenticated identifier.

DMARC compares the visible From domain with the domain validated by SPF and the signing domain in a valid DKIM signature. The message passes when at least one of those authenticated identifiers aligns. Relaxed alignment allows domains under the same organizational domain; strict alignment requires an exact match.

+
SPF or DKIMpasses + aligns
=
DMARCpass

This builder does not generate historic rollout tags.

RFC 9989 replaced the original DMARC specification in May 2026. Its active policy controls include p, sp, np, and test mode t. The older pct sampling tag is historic, so this tool does not generate it. The old ri and rfreporting tags are historic as well.

pPolicy for the domainActive
spPolicy for subdomainsActive
npPolicy for non-existent subdomainsActive
tStep policy down during testingActive
pctLegacy percentage samplingHistoric

Publishing reject does not repair authentication.

Start with reporting, identify every legitimate source, and correct its aligned DKIM or SPF identity. Forwarding and mailing lists can change the identifiers DMARC evaluates, so test real customer and employee flows. Receivers can consider the published request alongside other evidence; the policy does not guarantee a particular inbox or rejection outcome.

One domain should have one DMARC policy record at its policy location. Multiple competing records can make the policy unusable.

Before you touch DNS.

Does p=none protect the domain from spoofing?+

It enables DMARC evaluation and reporting but does not request quarantine or rejection for failures. Use the reports to make authorized mail align before enforcement.

What does t=y do?+

Under RFC 9989 it asks the receiver to apply policy one level below the published policy: quarantine becomes none and reject becomes quarantine. It has no practical effect with p=none.

Should I choose strict alignment?+

Not by default. Relaxed alignment already requires the same organizational domain and supports legitimate subdomain arrangements. Strict mode requires an exact domain match and can break mail that was deliberately configured with aligned subdomains.

Why does an external rua address need another DNS record?+

The report destination must opt in to reports for your policy domain. This prevents a domain owner from directing high-volume reports to an unwilling third party.

Can I publish this record immediately?+

The syntax can be copied immediately, but enforcement should wait until aggregate reports, sending-source inventory, authentication alignment, and indirect mail paths have been reviewed.

ALIGN EVERY STREAM

Send with authenticated infrastructure.

Manage sending domains, campaigns, product email, and delivery activity in one connected workspace.

Start for free