DMARC checker

Find out whether fake emails using your domain are blocked, and what each part of your DMARC record does.

How the DMARC check works

We look up the TXT record at _dmarc.yourdomain. If there isn’t one and you checked a subdomain, we look at the parent domain, because subdomains inherit its policy. We then read each tag: the policy (p=), the subdomain policy (sp=), the percentage (pct=), the report addresses (rua=) and the alignment settings (adkim= and aspf=). If reports go to another domain, we check that domain has published permission to receive them, as the DMARC standard (RFC 7489) requires.

The three policies

  • p=none: monitor only. Fake email is still delivered, but you receive reports. A safe first step, not a finishing line. What p=none really means.
  • p=quarantine: failing email goes to spam.
  • p=reject: failing email is refused. Full protection.

Common DMARC problems

  • More than one DMARC record: inboxes ignore them all.
  • No report address: you can’t see who is sending email on your behalf, so moving to quarantine or reject is guesswork.
  • A report address without mailto:: no reports will arrive.
  • Enforcing without DKIM: forwarded email fails SPF, so without DKIM your own genuine email can be blocked.

The DMARC record builder writes the record for each stage, and our guide to moving from none to reject sets out a week-by-week plan.

What does DMARC do?

It checks that an email claiming to be from your domain passed SPF or DKIM for your domain, the one shown in the From address. If it didn’t, your policy tells inboxes what to do: deliver it anyway (p=none), send it to spam (quarantine) or block it (reject). It also lets you receive reports on who is sending email on your behalf.

Is p=none enough?

No. It’s a safe first step for gathering reports, but fake emails still reach inboxes. Once your real email passes, move to quarantine and then reject.

Do I need DMARC if I’m a small business?

Yes. Since 2024, Gmail and Yahoo require DMARC for bulk senders, and Microsoft follows similar rules. It also stops fraudsters using your domain to deceive your customers.

Where do the reports go?

To the address in the rua tag. They arrive as XML files; a free DMARC report service can turn them into readable summaries. If the address is on a different domain, that domain has to publish a record agreeing to receive them. Report services do this for you, and we check it.

Why does an email pass SPF but fail DMARC?

Because it passed for someone else’s domain. Newsletter tools and CRMs often send with their own return address and signature, so SPF and DKIM pass for them, not for you. Set the tool up to sign with your domain (most call it “domain authentication”) and it will pass. Here’s how.

What can’t DMARC stop?

Lookalike domains, such as yourc0mpany.com, are a different domain with their own records, so your policy doesn’t cover them. Forwarded email can also fail SPF on the way, which is why DKIM matters before you move to quarantine or reject.