DMARC Generator & Analyzer
Generate and analyse DMARC records to protect a domain from spoofing and phishing.
DMARC configuration
Quick presets
Pick a starting point, then adjust anything below.
Not part of the record. Used to show the exact DNS host and to check whether your report addresses need external-destination verification.
How receivers should treat mail that fails authentication.
Policy for subdomains such as mail.example.com. Omitted, they inherit p.
0%100%
Share of messages the policy is applied to. Lower it for a gradual rollout.
Where the daily XML summaries go. Comma-separate several. The mailto: prefix is added for you.
Per-message failure reports. Most large receivers no longer send these, for privacy reasons.
Advanced options
Only has an effect when a ruf address is set.
A request, not a guarantee — receivers are free to send daily regardless.
AFRF is the only registered format and the default, so it is left out of the record.
Generated DMARC record
Record type
TXT
Host / name
_dmarc
TTL
3600 1 hour
Rollout guide
-
Step 1Start with monitoring
p=nonePublish in monitor mode first. Receivers keep delivering exactly as before and start sending you reports. -
Step 2Read the aggregate reports
ruaWork through a few weeks of reports and list every system that legitimately sends as the domain — CRMs, invoicing, help desks, the lot. -
Step 3Fix SPF and DKIM
aspf / adkimAuthorise each of those senders in SPF and give them valid DKIM signing. DMARC only passes when one of the two passes and aligns. -
Step 4Enforce gradually
p=quarantineMove to quarantine at a low percentage, watch the reports for collateral damage, then raise the percentage. -
Step 5Go to full protection
p=rejectFinish on reject at 100 percent, with a subdomain policy set, so spoofed mail is refused outright.
DMARC record input
The TXT value from _dmarc.<your-domain>. Surrounding quotes are fine.
Examples to try
Analysis results
Nothing analysed yet
Paste a DMARC record on the left and hit Analyse to see the breakdown.