/ developer & network toolbox
← all tools

$ dmarc pct

server-side

DMARC pct Tag Checker

Check a domain's DMARC pct value and learn what pct=100, pct=50 or pct=0 does to failing mail.

dmarc-pct — invoker.tools

About the DMARC pct Tag Checker

The pct tag in a DMARC record sets the percentage of failing messages that the policy applies to. pct=100, the default, means every message that fails DMARC gets the full policy. pct=25 with p=quarantine means a random quarter of failing messages are quarantined, while the rest are treated one step more leniently. Use the checker above to see the pct value, and every other tag, that a domain publishes right now.

The detail most explanations miss is what happens to the messages outside the percentage. They are not simply delivered as if DMARC did not exist. RFC 7489 tells receivers to apply the next less strict policy to them: with p=reject, the unselected messages are quarantined; with p=quarantine, they get no policy action. That is why pct=0 is not meaningless. p=reject; pct=0 quarantines every failing message while still signalling that reject is the goal.

pct only affects enforcement. Aggregate reports sent to the rua address cover all mail regardless of pct, so you keep full visibility while you ramp up. The usual rollout moves from p=none to p=quarantine at a low pct, raises it step by step while reports stay clean, and ends at p=reject with pct at 100 or the tag removed.

How to use it

  1. Enter a domain in the checker above and run the lookup.
  2. Find the pct row in the parsed tags. If it is missing, the policy applies to 100% of failing mail.
  3. Read pct together with p: the same pct means something different for quarantine and for reject.
  4. If a warning mentions pct below 100, decide whether the domain is still mid-rollout or simply forgot to finish.
  5. To change the value, rebuild the record with the DMARC generator and replace the TXT record at _dmarc.

Examples

  • p=quarantine; pct=100: every failing message goes to spam or quarantine.
  • p=quarantine; pct=50: half of the failing messages are quarantined, the other half get no policy action.
  • p=reject; pct=25: a quarter of failing messages are rejected, the remaining three quarters are quarantined.
  • p=reject; pct=0: nothing is rejected, but all failing messages are quarantined.
  • p=none; pct=10: pct has no effect, because none never takes action.

pct values and their effect

  • pct=100 (or no pct tag): the full policy for all failing mail. This is where every rollout should end.
  • pct=1 to 99: the policy for that share of failing mail, chosen at random per message, and the next weaker policy for the rest.
  • pct=0: the next weaker policy for all failing mail. Used as a cautious first step towards reject.
  • With p=none: pct is ignored, since there is no action to sample.

A typical pct ramp-up

  • p=none with rua, until reports show all legitimate senders aligned
  • p=quarantine; pct=10
  • p=quarantine; pct=50
  • p=quarantine (pct removed, so 100)
  • p=reject; pct=25, then remove pct once reports stay clean

pct and the updated DMARC specification

The revised DMARC specification (DMARCbis) drops pct because receivers applied random sampling inconsistently. In its place is a t tag for testing mode, where t=y asks receivers to apply the next weaker policy, the same effect as pct=0. Receivers still honour pct in records today, so existing records keep working, but for new records a clean pct=100 end state is the safest choice.

Frequently asked questions

What does pct=100 mean in DMARC?

The policy in p applies to 100% of messages that fail DMARC. It is the default, so a record without a pct tag behaves the same.

What happens to the messages not covered by pct?

They get the next less strict policy. Under p=reject they are quarantined, under p=quarantine they get no DMARC action.

Is pct=0 useful?

Yes, as a cautious step. p=reject; pct=0 quarantines all failing mail instead of rejecting it, while announcing that reject is the target.

Does pct affect DMARC reports?

No. Aggregate reports describe all mail for the domain, whatever the pct value.

Should I remove pct once I reach 100?

You can. pct=100 and no pct tag mean the same thing; removing it keeps the record shorter.

More email / dns tools