DMARC record checker
Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.
Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.
What we check
DMARC tells receivers what to do with mail that claims to come from a domain but fails SPF and DKIM checks, and where to send reports. We look for the record at _dmarc.<domain>. If there isn't one, we follow the DNS tree walk from RFC 9989 to find the policy a receiver would use, and say whether it is the domain's own or inherited from a parent.
The main settings
- p: the policy for the domain: none (monitor only), quarantine (treat as suspicious) or reject.
- sp and np: policies for subdomains that exist, and for names that don't exist.
- adkim and aspf: whether DKIM and SPF domains must match exactly (strict) or only share the organisational domain (relaxed).
- rua and ruf: where aggregate and failure reports go.
- t: test mode. "t=y" asks receivers not to apply the policy yet.
Older tags
RFC 9989 (May 2026) replaced the original DMARC specification, RFC 7489, and removed the pct, rf and ri tags. We still show them, because many records use them, but receivers following the new standard ignore them.
Frequently asked questions
What do p=none, quarantine and reject mean?
"none" asks receivers only to report, "quarantine" asks them to treat failing mail as suspicious (for example, the spam folder), and "reject" asks them to refuse it. Many domains start with "none" to collect reports, then move on once every sending service passes. We describe each one rather than say one is always right.
Why does a subdomain show its parent's policy?
If a name has no DMARC record of its own, receivers look further up the domain (the RFC 9989 tree walk). The parent's "sp" tag then applies to subdomains that exist, and "np" to names that don't exist; without them, "p" applies.
Why do you say pct was removed?
RFC 9989 (May 2026) replaced the original DMARC specification and dropped the pct, rf and ri tags. Many records still use them, so we show them, but receivers following the new standard ignore them. "t=y" is the new way to ask receivers not to apply the policy yet.
What is the report authorisation check?
If reports go to an address at a different organisation, that organisation must publish a record saying it accepts them. Without it, receivers may not send the reports. We check up to four destinations.
Do you store the report addresses?
No. They are public DNS data, shown only in your result. They are kept for a few minutes in the saved result and are never logged or counted.
Related tools
-
SPF Checker
Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.
-
MX Lookup
See which mail servers receive email for a domain, in priority order, with each server's addresses.
-
DNS Lookup
Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.
-
HTTP Header Checker
See the HTTP status and every response header a website sends, for the final page and each redirect on the way.
-
Redirect Checker
Follow a web address through every redirect, with the status code, destination and timing of each hop.
-
Website Health Check
Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.