DMARC record builder

Choose how strictly inboxes should treat fake email using your domain. We’ll build the record and explain every part.

Your domain

Already have a DMARC record? Load it to start from your current settings and move to the next step.

Policy for fake email
Reports

Gmail, Microsoft, Yahoo and others send daily reports directly to this address. Mail Health Report never sees them. Use a dedicated mailbox: reports arrive as XML files, and a DMARC report service can make them readable.

Subdomains
Advanced: alignment

Relaxed lets subdomains such as mail.yourdomain count as a match. Strict needs an exact match and can break some sending services.

Choosing the right DMARC policy

DMARC tells inboxes what to do with email that claims to be from your domain but wasn’t sent or signed by a service you’ve approved. The safe path takes about two months:

  1. Monitor (p=none) for two to four weeks with a report address. Reports list every server sending email using your domain.
  2. Fix your own senders. Any legitimate service that fails needs SPF or, better, DKIM set up for your domain.
  3. Quarantine (p=quarantine), starting at 25% and rising to 100% over a few weeks.
  4. Reject (p=reject) once reports show your real email passing. Fake email using your domain is then refused.

What the other settings do

  • Reports (rua): daily summaries from Gmail, Microsoft, Yahoo and others. They arrive as XML; a DMARC report service makes them readable. If the address is on another domain, that domain must publish permission to receive them.
  • Subdomain policy (sp): leave it unset so subdomains follow your main policy, unless you have a reason not to.
  • Alignment (adkim, aspf): relaxed lets mail.yourdomain count as a match for yourdomain. Strict needs an exact match and can break sending services, so keep relaxed unless you know you need strict.

After publishing, confirm the record with the DMARC checker. New to DMARC? Read what p=none means and the Gmail, Yahoo and Microsoft sender requirements.