← All toolsDNS record builder

DMARC Record Generator

Configure your DMARC policy and get a ready-to-publish DNS TXT record. Generated in your browser. Nothing sent to our servers.

Generated TXT record

v=DMARC1; p=none

_dmarc.example.com  IN  TXT  "v=DMARC1; p=none"

Generated in your browser. Nothing sent to our servers. Monitor your DMARC reports after publishing.

See plans →

Which policy should you start with?

Start with p=none and a reporting address. This lets you collect DMARC aggregate reports without affecting deliverability. Once you have confirmed that all your legitimate senders are authenticating correctly, move to p=quarantine and eventually p=reject. Skipping straight to reject can silently drop mail from ESPs you forgot to configure.

Frequently asked questions

Where does the DMARC record go in DNS?
Publish it as a TXT record at _dmarc.yourdomain.com. For example, if your domain is example.com, the record goes at _dmarc.example.com. Only one DMARC TXT record is valid per zone.
What happened to pct, and how do I test before enforcing?
RFC 9989 removed the pct tag, so newer receivers ignore it. To test a stricter policy first, turn on Testing / rollout mode above. It adds t=y; pct=0 to your record. t=y asks receivers to apply your policy one level softer (reject is handled as quarantine, quarantine as none). Both tags are there because older RFC 7489 receivers read pct and ignore t, while RFC 9989 receivers read t and ignore pct. Remove both tags when your reports look clean. More in why pct was deprecated and what changed in RFC 9989.
Do I need forensic reports (ruf)?
Not necessarily. Aggregate reports (rua) give you statistical data on all senders. Forensic reports (ruf) are per-message failure reports that can contain headers or redacted content. Many receivers do not send ruf reports due to privacy concerns. Start with rua only.
What is the difference between relaxed and strict alignment?
Relaxed alignment (the default) allows the signing domain to be an organizational domain match. For example, mail from mail.example.com aligns with a DMARC record at example.com. Strict alignment requires an exact domain match. Use relaxed unless you have a specific reason for strict.

Publishing a record is step one.

DMARCdrift parses your DMARC aggregate reports and shows which senders are passing alignment and which are failing. You will see issues before they affect deliverability.

Get started free →

After you publish your record, monitor it with DMARCdrift, free.

See plans →