Free tool · DMARC generator

A DMARC record in thirty seconds.

Pick a policy and where reports go. You get the record, the exact place to publish it, and what to watch out for.

Policy

p=none — reports only. Start here.

Subdomains
DKIM alignment
SPF alignment

Relaxed lets mail sent from a subdomain (news.example.fr) count for example.fr. Keep it unless you know you need strict.

TypeTXTHost / name_dmarc(on your domain)
v=DMARC1; p=none

No report address: you won't see who sends mail as your domain, which is the reason to start with p=none.

p=none only asks for reports. It meets Gmail and Yahoo's rule; move to quarantine once the reports show all your real mail passing.

Most DNS hosts want just _dmarc as the name. Once it's live, check it.

01How DMARC works

The rule for mail that fails SPF and DKIM.

DMARC ties SPF and DKIM to the address people see in From, tells receivers what to do when both fail, and sends you reports.

p=none

Start by watching

Nothing changes for your mail; you receive daily reports of every server sending as your domain. It meets Gmail and Yahoo's rule for bulk senders.

p=quarantine

Then send fakes to spam

Once the reports show your real mail passing, failing mail goes to the spam folder. Raise it gradually with pct if you're unsure.

p=reject

Finally, refuse them

Spoofed mail is refused outright. The end state for a domain that sends — it protects your name and your reputation.

rua

Reports are the point

Aggregate reports are XML files, one per receiver per day. A free report service turns them into a list of senders to approve.

Read more: SPF, DKIM and DMARC explained · SPF generator

02Questions

What people ask.

Is p=none enough for Gmail and Yahoo?
Yes. Since February 2024 they require a DMARC record from anyone sending them more than 5,000 emails a day, and p=none counts. It doesn't protect you from spoofing, though — that takes quarantine or reject.
Where does the record go?
A TXT record named _dmarc on your domain (most DNS hosts add the domain for you, so the name is just “_dmarc”). One record only.
Can reports go to another domain?
Yes, but that domain must accept them by publishing a small TXT record (yourdomain._report._dmarc.theirdomain). Report services do it for you; for your own second domain, add it yourself.
What about subdomains?
Without sp=, subdomains follow the main policy. Set a separate one if a subdomain sends mail you haven't authenticated yet — or to reject everything on subdomains that never send.
03Free tools

More free tools.

Deliverability, handled

Records right. Domain warmed. Then send.

Mailbase writes SPF, DKIM, DMARC and the reply MX when you add or buy a domain, then raises its volume only while real bounces and complaints stay low.