A DMARC checker resolves the TXT record your DNS serves at _dmarc.yourdomain and reads it the way a receiving mail server would. That is not always the DMARC record you think you published — panels split long values, and plenty of records end up at the domain root by mistake.
The free DMARC record checker parses v, p, sp, pct, rua, ruf, aspf, and adkim, then reports what a receiver would actually do with failing mail. It is a DMARC record checker and validator rather than a raw TXT lookup.
Run the DMARC checker after every publish and at every policy change. DMARC fails silently: nothing tells you a record stopped parsing except spoofed mail arriving in inboxes weeks later.
p= (Policy)
The policy. What the DMARC checker reports as the effective action on failing mail: none, quarantine, or reject.
sp= (Subdomain Policy)
Subdomain policy. Without it subdomains inherit p; the DMARC checker reports the inherited value explicitly.
pct= (Percentage)
Share of failing mail the policy applies to. A DMARC checker reads pct=25 as a partial rollout, not a full one.
rua= (Aggregate Reports)
Aggregate report address. A DMARC checker flags a p=none record with no rua as monitoring that reports nothing.
ruf= (Forensic Reports)
Forensic report address. Optional, and increasingly ignored by receivers, so the DMARC checker treats it as informational.
adkim= (DKIM Alignment)
DKIM alignment mode. Strict breaks subdomain signing, and the DMARC checker calls that out.
aspf= (SPF Alignment)
SPF alignment mode, relaxed or strict. The DMARC checker reports which one is in force.
fo= (Failure Options)
Forensic reporting options. Rarely load-bearing, but the DMARC checker parses it for completeness.