1. Home
  2. Free tools
  3. DMARC generator

DMARC record generator

Pick a policy, add a reporting address, and this builds the DMARC TXT record to publish at _dmarc on your domain. The policy is the whole point of the record: p=none turns reporting on but blocks nothing, so the generator says so rather than letting you think you are protected.

Policy

Daily XML summaries of what passed and failed, per sending source. This is how you find the vendor nobody told you about that has been sending as your domain for a year. The files are unreadable by hand — point them at a parsing service.

Advanced options

Set sp=reject even while the main policy is relaxed — unused subdomains are a common spoofing route.

Roll out enforcement gradually. Only meaningful with quarantine or reject.

Your DMARC record

v=DMARC1; p=none

p=none enforces nothing. This record satisfies Google and Yahoo’s bulk-sender requirement and turns reporting on, but anyone can still spoof your domain. Read the reports for a few weeks, confirm every legitimate sender passes, then move to quarantine and then reject.

No reporting address set. Without rua= you get no visibility into who is sending as your domain, which is most of the value of DMARC.

Where this goes in DNS

Type
TXT
Name / host
_dmarc
Value
the record above

The hostname is _dmarc, not the root domain — that is the most common mistake. DMARC also needs SPF or DKIM already working to be useful, since it only decides what to do when those fail.

Most DMARC records do nothing

When Google and Yahoo began requiring DMARC on bulk senders in February 2024, a very large number of domains published v=DMARC1; p=none and considered the job done. That record satisfies the requirement. It also permits anyone on the internet to send mail that appears to come from the domain.

The protection arrives only at p=quarantine or p=reject. Getting there is not risky if you do it in order: publish p=none with a reporting address, spend two to four weeks reading what the reports show, fix or remove the senders that fail, then raise the policy. The reports are the part people skip, and they are the part that makes the move safe.

One shortcut worth taking immediately: set sp=reject even while your main policy is still none. Your unused subdomains send no legitimate mail, so there is nothing to break, and they are a favourite spoofing route precisely because nobody sets a policy on them.

Then check it worked

DNS changes take minutes to hours to propagate. Once published, confirm it with the DMARC checker, and confirm the records it depends on with the SPF checker and DKIM checker. The full audit runs all of them at once and scores the domain.

If you do not have SPF yet, build that first with the SPF generator — DMARC has nothing to act on until SPF or DKIM is in place.

Common questions

How do I create a DMARC record?
Choose a policy, add an address for aggregate reports, and publish the result as a TXT record at _dmarc.yourdomain.com. The generator above builds the record and warns you when the settings will not actually enforce anything.
What DMARC policy should I start with?
Start at p=none with a reporting address. It cannot break legitimate mail, and the reports show you every source sending as your domain — usually including one or two you had forgotten about. Move to quarantine once those all pass authentication, then to reject.
Where does the DMARC record go?
At the hostname _dmarc on your domain, so _dmarc.yourdomain.com, as a TXT record. Putting it on the root domain instead is the most common DMARC mistake and means no receiver will ever find it.
Is p=none enough for Google and Yahoo?
Yes, technically. Since February 2024 both require a DMARC record on domains sending bulk mail, and p=none satisfies that. But it enforces nothing — anyone can still spoof your domain, and p=none was never meant to be a destination. It is the monitoring phase.
Do I need SPF and DKIM before DMARC?
Yes. DMARC does not authenticate anything itself; it only decides what happens when SPF and DKIM fail, and whether the domain that passed matches the visible From address. Publishing DMARC with neither in place means everything fails it, which is why you start at p=none.
What is DMARC alignment?
The requirement that the domain which passed SPF or DKIM matches the domain in the From header a recipient sees. It is what makes the other two records useful — without it a spammer could pass SPF for a domain they own while displaying yours. Relaxed alignment, the default, lets a subdomain match the parent; strict requires an exact match and often breaks email service providers.

Records published. Now the list itself.

Authentication stops your mail being forged. It does nothing about the dead addresses that get you throttled in the first place.

  • Bulk verification with real SMTP mailbox checks
  • Hard bounces removed before a send, not discovered after
  • Catch-all, disposable and role detection on every row

One plan, cancel anytime, no contract. The free tools stay free and unmetered either way — they are not a trial.

Ready to clean your email lists?

Start verifying emails today and boost your deliverability.

Get Started

Cancel anytime • No setup required