Validate your DMARC record

Is your DMARC record correct? The DMARC Check validates syntax, policy and reporting configuration and shows whether your domain is protected against email spoofing – including a concrete recommendation for the next step.

FreeAccount requiredResults in seconds

Guest mode: limited usage. Register for free for unlimited usage, history & statistics.

Register free

Check your DMARC record

Enter a domain to check its DMARC DNS configuration. We analyze the record for security issues, missing tags, and optimization potential.

How it works

1

1. Enter domain

Enter the domain whose DMARC setup you want to check.

2

2. Evaluate record

The checker reads and validates the _dmarc TXT record.

3

3. Implement recommendation

You get a clear recommendation – from the first p=none to p=reject.

Features in detail

Syntax validation

Instant check for typos and invalid parameters.

Policy recommendation

p=none, quarantine or reject? We recommend the right level.

SPF/DKIM alignment

Check whether SPF and DKIM are properly aligned for DMARC.

Reporting configuration

rua/ruf addresses and report intervals at a glance.

Monitoring integration

Directly move on to DMARC analysis with AI threat detection.

No account needed

The check is free and without login.

Frequently asked questions

What is a DMARC record?

A DMARC record is a TXT record in DNS at _dmarc.your-domain.com. It defines the policy (p=none, quarantine, or reject) and the report addresses (rua/ruf) where mail providers send their reports.

How do I create a DMARC record?

Add a TXT record at _dmarc.your-domain.com, e.g.: v=DMARC1; p=none; rua=mailto:dmarc@your-domain.com. Start with p=none, analyze reports for a few weeks, then harden to quarantine or reject.

What do p=none, p=quarantine and p=reject mean?

p=none: nothing is blocked, reports only (entry level). p=quarantine: unauthenticated mail goes to spam. p=reject: unauthenticated mail is rejected — the strongest anti-spoofing level.

Why do emails land in spam even though SPF and DKIM are correct?

SPF and DKIM verify the technical sender — without DMARC they do not check the visible From-domain (alignment). An attacker can pass SPF/DKIM for their own domain while spoofing yours. DMARC closes exactly this gap.

What is the difference between rua and ruf?

rua = aggregate reports: daily summaries of all delivery attempts (volume, alignment). ruf = forensic reports: individual rejected emails in full — privacy-sensitive, only supported by a few providers.

How fast does a DMARC record take effect?

The DNS record is picked up globally within minutes to 48 hours depending on TTL. Reports from major providers (Google, Microsoft) start the next day. Policy changes apply to new mail immediately.

Can DMARC break email forwarding?

Yes, classic forwarding can break SPF (the forwarding server becomes the sender) and DKIM can break through modification. DMARC reports show which legitimate forwarding paths are affected — solutions are ARC or SRS.

Do I need DMARC if I have SPF and DKIM?

Yes. SPF and DKIM do not protect against spoofing of the visible sender. Only DMARC connects both and defines what happens on failures.

Which DMARC policy should I choose?

Start with p=none (monitor only), then raise to quarantine and finally reject after evaluating reports. The check shows you the recommended path.

What do rua and ruf mean?

rua = address for aggregate reports (delivery statistics), ruf = address for forensic single reports (concrete failures). Both can point to our analysis address.

Related guides