Email

DMARC Record Lookup

DMARC Policy

Look up DMARC records

Enter a domain to check its DMARC policy, alignment modes, and reporting configuration.

DNS Resolver

Most domains return the same records on every resolver — the choice matters during DNS propagation, or when a filtering resolver blocks a domain.

Tool features

Comprehensive DMARC record analysis with policy validation and security assessment
4 checks

DMARC Policy Analysis

Comprehensive analysis of DMARC policy records and settings

Email Authentication

Check email authentication policies for domain protection

Policy Validation

Validate DMARC syntax and policy configuration

Security Assessment

Assess email security posture and configuration strength

What is DMARC & how it works

The policy that stops others spoofing your domain

DMARC (Domain-based Message Authentication, Reporting & Conformance) is the email policy that ties SPF and DKIM together. Published as a TXT record at _dmarc.yourdomain.com, it tells receiving mail servers what to do with messages that fail authentication — monitor, quarantine, or reject — and where to send reports.

This lookup fetches and parses your DMARC record, showing the enforcement policy, alignment modes, reporting addresses, and percentage covered. It flags the two states that leave a domain exposed: no DMARC record at all, and a record stuck on p=none, which monitors but never actually blocks spoofed mail.

p= policy
The enforcement action: none (monitor only), quarantine (send to spam), or reject (block outright).
Alignment
Whether the SPF/DKIM domain matches the visible From domain. Strict or relaxed alignment controls how closely.
rua / ruf
The addresses that receive aggregate (rua) and forensic (ruf) DMARC reports about your mail.

How to use this tool

Check a domain's DMARC policy in four steps
1
Enter a domain name
Type the domain whose DMARC policy you want to inspect, e.g. example.com.
2
Run the lookup
We query the _dmarc TXT record and parse each tag in the policy.
3
Review the policy
Check the enforcement level (p=), alignment, coverage, and reporting addresses.
4
Strengthen enforcement
Move from p=none toward quarantine or reject once your legitimate mail passes authentication.

Related tools

Keep debugging with tools from the same suite
5 tools
DMARC Generator
Generate DMARC policy records for email authentication with policy configuration options
DMARC Report (RUA) Analyzer
Summarize DMARC aggregate (RUA) report XML: sending sources, SPF/DKIM alignment, volumes, and spoofing signals
SPF Lookup
Check Sender Policy Framework (SPF) records for email authentication and mail server authorization
DKIM Lookup
Find DomainKeys Identified Mail (DKIM) records for email message signing and verification
Email Health Checker
Comprehensive email deliverability check including SPF, DKIM, DMARC, and MX records

Frequently asked questions

Common questions about DMARC records
5 Q&A

p=none is monitor-only: receivers still deliver mail that fails DMARC, but send you reports. It's the safe starting point, but it provides no protection — the goal is to progress to quarantine or reject.

Quarantine tells receivers to treat failing mail as suspicious (usually routing it to spam). Reject tells them to refuse it outright. Reject is the strongest protection against spoofing of your domain.

Yes. DMARC builds on SPF and DKIM — a message passes DMARC when it passes SPF or DKIM and the authenticated domain aligns with the From domain. Without them, DMARC has nothing to enforce.

They are daily XML summaries from receiving servers showing which sources sent mail as your domain and whether it passed authentication — invaluable for finding legitimate senders before you enforce.

If your policy is p=none, receivers won't block spoofed mail. You also need SPF and DKIM aligned for all legitimate senders, then raise the policy to quarantine or reject to actually stop spoofing.