DMARC record builder
Choose how strictly inboxes should treat fake email using your domain. We’ll build the record and explain every part.
Choosing the right DMARC policy
DMARC tells inboxes what to do with email that claims to be from your domain but wasn’t sent or signed by a service you’ve approved. The safe path takes about two months:
- Monitor (
p=none) for two to four weeks with a report address. Reports list every server sending email using your domain. - Fix your own senders. Any legitimate service that fails needs SPF or, better, DKIM set up for your domain.
- Quarantine (
p=quarantine), starting at 25% and rising to 100% over a few weeks. - Reject (
p=reject) once reports show your real email passing. Fake email using your domain is then refused.
What the other settings do
- Reports (
rua): daily summaries from Gmail, Microsoft, Yahoo and others. They arrive as XML; a DMARC report service makes them readable. If the address is on another domain, that domain must publish permission to receive them. - Subdomain policy (
sp): leave it unset so subdomains follow your main policy, unless you have a reason not to. - Alignment (
adkim,aspf): relaxed letsmail.yourdomaincount as a match foryourdomain. Strict needs an exact match and can break sending services, so keep relaxed unless you know you need strict.
After publishing, confirm the record with the DMARC checker. New to DMARC? Read what p=none means and the Gmail, Yahoo and Microsoft sender requirements.