/ developer & network toolbox
← all tools

$ dmarc+

runs locally

DMARC Generator

Build a valid DMARC record tag by tag: policy, pct, reporting addresses and alignment, with a plain-English explanation of every tag.

dmarcgen — invoker.tools
typeTXT
host_dmarc
v=DMARC1; p=none
v=DMARC1Identifies the record as DMARC. Must come first.
p=noneMonitor only: failing mail is delivered as normal, you just receive reports.
⚠ p=none does not stop spoofing. Use it to collect reports first, then move to quarantine and reject.
⚠ No rua address: you will not see who sends mail as your domain, which makes tightening the policy guesswork.

About the DMARC Generator

This DMARC generator builds a correct _dmarc TXT record from a few choices: the policy (none, quarantine or reject), an optional subdomain policy, the percentage of mail the policy applies to, where aggregate and failure reports should go, and whether SPF and DKIM alignment should be relaxed or strict. The record updates live as you change settings, and each tag in it is explained in plain English right underneath, so you know exactly what you are about to publish.

The generator leaves out tags that only repeat a default. pct=100, adkim=r, aspf=r and ri=86400 are what receivers assume anyway, so the output stays short and readable. It also warns about the mistakes that show up most often in real DMARC records: p=none left in place for years, a missing rua address, a pct below 100 at the end of a rollout, fo without ruf, and reports sent to another domain that has not authorised them.

DMARC sits on top of SPF and DKIM. It tells receiving mail servers what to do with a message whose From domain is not backed by an aligned SPF or DKIM pass, and where to send reports about it. Since February 2024 Google and Yahoo require at least a p=none DMARC record from bulk senders, so every domain that sends mail should have one.

Everything runs in your browser. Nothing you type is sent to a server; publish the record at your DNS provider and then verify it with the DMARC checker.

How to use it

  1. Enter your domain so the host name (_dmarc.example.com) and report authorisation hints are filled in.
  2. Choose a policy. Start with none if you have never looked at DMARC reports for this domain.
  3. Add at least one rua address for aggregate reports; a dedicated mailbox or a DMARC report service works best.
  4. Leave pct at 100 unless you are stepping up to quarantine or reject gradually.
  5. Keep adkim and aspf relaxed unless you have a specific reason to require exact domain matches.
  6. Copy the record and publish it as a TXT record on the _dmarc host at your DNS provider.
  7. Run the DMARC checker a few minutes later to confirm the live record parses as expected.

Examples

  • Monitoring start: v=DMARC1; p=none; rua=mailto:dmarc@example.com
  • Careful enforcement: v=DMARC1; p=quarantine; pct=25; rua=mailto:dmarc@example.com
  • Full protection: v=DMARC1; p=reject; rua=mailto:dmarc@example.com
  • Strict main domain, parked subdomains: v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; rua=mailto:dmarc@example.com
  • Reports to a service on another domain: v=DMARC1; p=none; rua=mailto:abc123@reports.example-dmarc.net (that service must publish example.com._report._dmarc.reports.example-dmarc.net)

Which DMARC tags do you actually need?

  • v=DMARC1 and p are required. Everything else is optional.
  • rua is optional in the standard but essential in practice: without reports you cannot tell whether moving to reject will break legitimate mail.
  • sp only matters when subdomains need a different policy than the main domain.
  • pct is a rollout tool. Use it while moving to quarantine or reject, then remove it (100 is the default).
  • adkim and aspf default to relaxed, which is right for almost every domain.
  • ruf and fo control per-message failure reports. Most large mailbox providers no longer send them, so they are rarely worth adding.

External report addresses need authorisation

When the rua or ruf address is on a different domain than the one publishing the DMARC record, receivers check that the report domain agreed to receive them. The report domain publishes a TXT record with the value v=DMARC1 at <your-domain>._report._dmarc.<report-domain>. DMARC report services create this for their customers automatically; if you point reports at a mailbox on another domain you own, you have to add it yourself, or the reports silently never arrive.

Where to publish the record

Create a TXT record whose name is _dmarc under your domain. Some DNS panels want the full name (_dmarc.example.com), others only the prefix (_dmarc) and append the domain for you; check the result with a DNS lookup if you are unsure. There must be exactly one DMARC record: two TXT records starting with v=DMARC1 make receivers ignore DMARC for the domain altogether.

Frequently asked questions

What is a good DMARC record to start with?

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. It changes nothing for delivery but starts the daily aggregate reports, which show every source sending mail as your domain.

How long should I stay on p=none?

Until the reports show that all legitimate sources pass SPF or DKIM with alignment. For most organisations that takes a few weeks; after that, step up to quarantine and then reject.

Should I use p=quarantine or p=reject?

Reject gives the strongest protection against spoofing because failing messages are refused outright. Quarantine is a safer intermediate step: failing mail goes to spam, where it can still be found if a legitimate sender was missed.

Do I need a ruf address?

Usually not. Failure reports contain parts of individual messages, and for privacy reasons most large receivers stopped sending them. Aggregate reports via rua are what you need.

Can I have more than one DMARC record?

No. A domain must publish exactly one TXT record starting with v=DMARC1 at _dmarc. With two, receivers treat the domain as having no valid DMARC policy.

Does this generator publish the record for me?

No, it only builds the text. Add it as a TXT record at your DNS provider, then use the DMARC checker to confirm it is live.

More email / dns tools