Email

DMARC Record Generator

Policy Record

Build your DMARC record

Choose what happens to failing mail, where the reports go, and how strictly SPF and DKIM must align.
DomainrequiredWhat's this?
The domain you send mail from. Everything below is published as one TXT record under it.
Publishes at _dmarc.yourdomain.com. “Look up existing” fetches the record already published so you can edit it.
Already have a record?paste · optionalWhat's this?
Paste a DMARC record from anywhere — another domain, a vendor’s guide, a draft — to prefill the wizard with it.
Step 1 of 4

Finish the wizard to build your record

Work through the four steps above, then press Generate on the last step to produce your DMARC record.

Tool features

Everything you need to build and publish a correct DMARC record
4 checks

Guided four-step wizard

Domain, policy, reporting, then alignment — no DMARC syntax to memorize

Multiple report addresses

Add as many rua and ruf destinations as you need, each validated as you type

Live validation

Every record ships with a checklist covering policy strength, coverage, alignment and privacy

Share & export

Share the record or download it as a branded PDF, JSON payload or zone-file line

What is a DMARC record & how it works

Turning SPF and DKIM into active anti-spoofing protection

A DMARC record is a DNS TXT record at _dmarc.yourdomain.com that tells receiving mail servers how to handle messages that fail SPF and DKIM authentication — monitor, quarantine, or reject — and where to send reports. It's what turns SPF and DKIM from passive checks into active protection against spoofing.

This generator builds a valid DMARC record from your choices: the enforcement policy, the percentage of mail it applies to, alignment modes, and the addresses that receive aggregate and forensic reports. Start in monitoring mode to see who sends as your domain, then tighten the policy once your legitimate mail passes.

Every field in the wizard — p, pct, rua, ruf,fo, the alignment tags and sp — is explained one by one in DMARC Generator: Every Input Explained — the same copy behind every “What's this?” link above.

p= policy
The action for failing mail: none (monitor), quarantine (spam folder), or reject (block).
rua
The address that receives aggregate reports — daily summaries of who is sending as your domain.
pct
The percentage of mail the policy applies to, useful for gradually rolling out enforcement.

How to use this tool

Build and publish a DMARC record in four steps
1
Enter your domain
Start with the domain you want to protect, for example example.com.
2
Choose a policy
Begin with p=none to monitor, then move to quarantine or reject as you gain confidence.
3
Add reporting addresses
Set the rua (and optional ruf) addresses that will receive DMARC reports.
4
Publish the record
Copy the generated TXT record and add it at _dmarc.yourdomain.com in your DNS.

Related tools

Keep debugging with tools from the same suite
5 tools
DMARC Lookup
Check DMARC policy records for email authentication, reporting, and policy enforcement
DMARC Report (RUA) Analyzer
Summarize DMARC aggregate (RUA) report XML: sending sources, SPF/DKIM alignment, volumes, and spoofing signals
SPF Generator
Generate SPF records to authorize mail servers for your domain with visual builder
DKIM Generator
Generate DKIM keys and records for email message signing and authentication
Email Health Checker
Comprehensive email deliverability check including SPF, DKIM, DMARC, and MX records

Frequently asked questions

Common questions about DMARC records
5 Q&A

Start with p=none. It's monitor-only: you receive reports about who sends as your domain without affecting delivery. Once your legitimate senders all pass SPF/DKIM, move to quarantine and then reject.

Add it as a TXT record with the host _dmarc (i.e. _dmarc.yourdomain.com) and the value being the generated v=DMARC1 ... string.

rua receives aggregate reports — daily XML summaries of authentication results across all your mail. ruf receives forensic reports — individual failure samples. rua is the one most people rely on.

Yes. DMARC evaluates SPF and DKIM results, so both should be configured and aligned for your legitimate senders before you enforce a strict DMARC policy — otherwise valid mail may be blocked.

pct sets the percentage of mail the policy applies to. Setting pct=25 with p=quarantine, for example, applies quarantine to a quarter of failing mail — handy for a gradual rollout.