Skip to main content
WebTools

DMARC record checker

Find the DMARC policy that applies to a domain, see what each setting means, and spot mistakes that make receivers ignore it.

Choosing a check opens its page. With the keyboard, use the arrow keys, then press Enter.

What we check

DMARC tells receivers what to do with mail that claims to come from a domain but fails SPF and DKIM checks, and where to send reports. We look for the record at _dmarc.<domain>. If there isn't one, we follow the DNS tree walk from RFC 9989 to find the policy a receiver would use, and say whether it is the domain's own or inherited from a parent.

The main settings

Older tags

RFC 9989 (May 2026) replaced the original DMARC specification, RFC 7489, and removed the pct, rf and ri tags. We still show them, because many records use them, but receivers following the new standard ignore them.

Frequently asked questions

What do p=none, quarantine and reject mean?

"none" asks receivers only to report, "quarantine" asks them to treat failing mail as suspicious (for example, the spam folder), and "reject" asks them to refuse it. Many domains start with "none" to collect reports, then move on once every sending service passes. We describe each one rather than say one is always right.

Why does a subdomain show its parent's policy?

If a name has no DMARC record of its own, receivers look further up the domain (the RFC 9989 tree walk). The parent's "sp" tag then applies to subdomains that exist, and "np" to names that don't exist; without them, "p" applies.

Why do you say pct was removed?

RFC 9989 (May 2026) replaced the original DMARC specification and dropped the pct, rf and ri tags. Many records still use them, so we show them, but receivers following the new standard ignore them. "t=y" is the new way to ask receivers not to apply the policy yet.

What is the report authorisation check?

If reports go to an address at a different organisation, that organisation must publish a record saying it accepts them. Without it, receivers may not send the reports. We check up to four destinations.

Do you store the report addresses?

No. They are public DNS data, shown only in your result. They are kept for a few minutes in the saved result and are never logged or counted.

  • SPF Checker

    Check that a domain's SPF record is valid, stays within the 10-lookup limit, and says what you expect about servers that may send its mail.

  • MX Lookup

    See which mail servers receive email for a domain, in priority order, with each server's addresses.

  • DNS Lookup

    Look up the DNS records published for a domain, one type or all common types at once, or the reverse DNS name of an IP address.

  • HTTP Header Checker

    See the HTTP status and every response header a website sends, for the final page and each redirect on the way.

  • Redirect Checker

    Follow a web address through every redirect, with the status code, destination and timing of each hop.

  • Website Health Check

    Run the main website, DNS and email checks on one site at once and get a short report, area by area, with links to the full results.