Monitor authentication results; no quarantine or rejection is requested.
DMARC record
builder
Build a current DMARC policy, understand exactly what it asks receivers to do, and catch risky rollout choices before changing DNS.
- RFC 9989 tags
- Rollout readiness
- No domain data sent
Advanced controls +
Ready to copy—not yet ready to publish.
_dmarc.example.comv=DMARC1; p=none; rua=mailto:[email protected]_dmarc.example.com. 3600 IN TXT "v=DMARC1; p=none; rua=mailto:[email protected]"DKIM or SPF may align through the same organizational domain.
aggregate report destination(s) requested
Record syntax looks coherent.
Publication safety still depends on complete SPF and DKIM coverage for your real sending sources.
0/5 checks complete.
Move policy only after the evidence moves.
- 01Monitor
Publish p=none with aggregate reporting and inventory every authorized source found in reports.
- 02Align
Make at least one authenticated identifier align for every legitimate stream—preferably both DKIM and SPF.
- 03Test
Use p=quarantine with t=y, then remove test mode when reports show expected mail remains healthy.
- 04Enforce
Move through quarantine to reject only when aggregate evidence and operational ownership support it.
A pass needs one aligned authenticated identifier.
DMARC compares the visible From domain with the domain validated by SPF and the signing domain in a valid DKIM signature. The message passes when at least one of those authenticated identifiers aligns. Relaxed alignment allows domains under the same organizational domain; strict alignment requires an exact match.
Publishing reject does not repair authentication.
Start with reporting, identify every legitimate source, and correct its aligned DKIM or SPF identity. Forwarding and mailing lists can change the identifiers DMARC evaluates, so test real customer and employee flows. Receivers can consider the published request alongside other evidence; the policy does not guarantee a particular inbox or rejection outcome.
One domain should have one DMARC policy record at its policy location. Multiple competing records can make the policy unusable.
Before you touch DNS.
Does p=none protect the domain from spoofing?+
It enables DMARC evaluation and reporting but does not request quarantine or rejection for failures. Use the reports to make authorized mail align before enforcement.
What does t=y do?+
Under RFC 9989 it asks the receiver to apply policy one level below the published policy: quarantine becomes none and reject becomes quarantine. It has no practical effect with p=none.
Should I choose strict alignment?+
Not by default. Relaxed alignment already requires the same organizational domain and supports legitimate subdomain arrangements. Strict mode requires an exact domain match and can break mail that was deliberately configured with aligned subdomains.
Why does an external rua address need another DNS record?+
The report destination must opt in to reports for your policy domain. This prevents a domain owner from directing high-volume reports to an unwilling third party.
Can I publish this record immediately?+
The syntax can be copied immediately, but enforcement should wait until aggregate reports, sending-source inventory, authentication alignment, and indirect mail paths have been reviewed.
Send with authenticated infrastructure.
Manage sending domains, campaigns, product email, and delivery activity in one connected workspace.
Start for free