Free Tool

DMARC Record Generator

Create a valid DMARC TXT record for your domain. Choose policy, alignment, reporting addresses, and rollout percentage.

Generate Your DMARC Record

Percentage of failing messages to apply the policy to. Use a low value when rolling out quarantine or reject.

What Is DMARC and Why Do You Need It?

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is the third pillar of email authentication, building on top of SPF and DKIM. It tells receiving mail servers what to do when a message fails authentication checks, and where to send reports about those failures. Without DMARC, having SPF and DKIM in place is necessary but not sufficient β€” an attacker can still forge your visible From address even if SPF and DKIM pass on a different domain.

Gmail, Yahoo, and Microsoft have all made DMARC a requirement for bulk senders. Domains without a DMARC policy face increased spam filtering and reduced inbox placement across major mailbox providers.

The Three DMARC Policy Levels

DMARC uses a graduated rollout approach with three policy levels. The recommended sequence is to start at none, move to quarantine, and ultimately reach reject.

  • p=none β€” Monitor only. Failing messages are delivered normally, but aggregate reports are sent to the rua address. Use this to discover all your sending sources before enforcing policy.
  • p=quarantine β€” Failing messages go to the spam folder. Use this once you have verified your legitimate mail passes authentication.
  • p=reject β€” Failing messages are rejected outright. This is the strongest protection and the goal for most domains.

Understanding DMARC Alignment

DMARC passes when either SPF or DKIM passes and the authenticated domain aligns with the From header domain. Relaxed alignment (r) allows subdomain matches β€” for example, mail.example.com aligns with example.com. Strict alignment (s) requires an exact domain match. Start with relaxed alignment and only tighten to strict if you have a specific reason.

DMARC Reporting: rua vs ruf

The rua tag specifies the email address to receive aggregate reports β€” daily XML summaries of authentication results from all senders worldwide. These are essential for understanding your sending footprint and catching unauthorized senders. The ruf tag specifies the address for forensic (failure) reports, which contain details of individual failing messages. Forensic reports are less widely supported and may contain message content, so they require more careful handling.

You can receive reports at any email address β€” even one on a different domain. Some organizations use dedicated DMARC report processing services to parse and visualize aggregate XML data.

Completing Your Email Authentication Setup

DMARC works best as the final layer on top of SPF and DKIM. Set up SPF to authorize your sending IPs, configure DKIM signing on your mail server or email service provider, and then add a DMARC policy to tie everything together and receive reports.

Authentication protects you from domain abuse. List hygiene protects your sender reputation. Use email verification to remove invalid addresses before every send, or check large lists with bulk email verification. See pricing for verification plans.

Frequently Asked Questions

1. Where do I publish a DMARC record?

Publish a TXT record at _dmarc.yourdomain.com with the value generated by this tool (starting with v=DMARC1;).

2. Should I start with p=none?

Yes for almost every domain. Start with p=none and a valid rua address so you can see who sends as your domain before you quarantine or reject.

3. What is the pct tag for?

pct controls what percentage of failing messages receive the quarantine or reject policy. Use a low pct when first enforcing policy, then raise it to 100.

4. Do I need both SPF and DKIM for DMARC to pass?

DMARC passes if either SPF or DKIM passes with alignment. Having both is strongly recommended for reliability, especially when mail is forwarded.

5. What are rua reports?

Aggregate XML reports sent daily by receivers. They show how much mail passed or failed SPF/DKIM/DMARC for your domain and which sources were involved.

6. Is DMARC required for bulk senders?

Major providers including Gmail and Yahoo require DMARC (at least p=none) for bulk senders. Without it, deliverability suffers.

Next Step

Verify and clean your email list

Authentication protects your domain. Clean lists protect your reputation. BillionVerify verifies addresses with SMTP-level accuracy.

100 free verifications daily Β· 99.9% SMTP accuracy Β· Instant API access Β· No credit card required

99.9%
Accuracy
Real-time
API Speed
$0.00014
Per Email
100/day
Free Forever