Back to Tools

DMARC Record Generator

Create a DMARC policy record to protect your domain from email spoofing and phishing. Configure policy, reporting, alignment, and gradual rollout with our free generator.

About this tool

Around 3.4 billion phishing emails are sent every single day, and without DMARC, your domain could be one of the ones being spoofed. DMARC builds on SPF and DKIM to give you explicit control over what happens when someone sends an email that fails authentication checks for your domain. It's the policy layer that turns passive authentication into active protection.

How DMARC Records Work

A DMARC record is a DNS TXT record published at _dmarc.yourdomain.com. Here's what a full record looks like: v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; ruf=mailto:forensic@yourdomain.com; adkim=s; aspf=s; pct=100. The key fields are: p (policy: none, quarantine, or reject), rua (where aggregate reports go), ruf (where forensic reports go), adkim/aspf (alignment mode: strict or relaxed), and pct (percentage of emails the policy applies to). This generator walks you through each option so you don't have to memorize the syntax.

The p=none to p=reject Progression

Jumping straight to p=reject is the fastest way to break your own email. The correct progression is: start with p=none and enable reporting so you can see every service sending email as your domain. After 2-4 weeks of reviewing aggregate reports, move to p=quarantine; pct=10 to quarantine 10% of failing emails. Gradually increase pct to 100, then switch to p=reject with the same gradual rollout. The entire process typically takes 6-12 weeks for a domain with multiple sending services. Rushing it means legitimate emails from your CRM, helpdesk, or transactional system get quarantined or rejected.

Common Mistakes That Break Email

The biggest mistake is not including all your sending services in SPF/DKIM before tightening your DMARC policy. If your marketing team uses Mailchimp, support uses Zendesk, and engineering sends transactional emails through SendGrid, all three need proper authentication before you move past p=none. Another common error is ignoring the aggregate reports—they're the whole point of the monitoring phase. Use a service like Postmark's DMARC monitoring or dmarcian to parse the XML into readable dashboards.

Fit It Into Your Authentication Workflow

DMARC doesn't work in isolation. First, generate your SPF record covering all sending services, then set up DKIM signing for each service. Once both are passing, use this generator to create your DMARC record. Verify everything is live with the DMARC checker and DNS propagation checker. Run a full deliverability audit quarterly to make sure nothing's drifted.

Frequently Asked Questions

What is DMARC and why do I need it?

DMARC (Domain-based Message Authentication, Reporting & Conformance) tells receiving servers what to do with emails that fail SPF or DKIM checks. Without it, anyone can send email pretending to be your domain. Google and Yahoo now factor DMARC into deliverability decisions, so even if you're not worried about phishing, you need it for inbox placement.

What DMARC policy should I start with?

Always start with p=none and enable rua reporting. This is monitor-only mode—no emails get blocked, but you receive daily reports showing every IP that sent email as your domain. After 2-4 weeks of reviewing reports and confirming all legitimate senders pass authentication, move to p=quarantine with pct=10 and scale up gradually.

What do p=none, p=quarantine, and p=reject actually do?

p=none tells receivers to do nothing with failing emails (just report them). p=quarantine tells receivers to send failing emails to spam. p=reject tells receivers to outright refuse failing emails. The progression from none to reject typically takes 6-12 weeks for domains with multiple sending services.

What are DMARC aggregate reports and how do I read them?

Aggregate reports (rua) are daily XML files from mail servers showing who sent email using your domain, which IPs they used, and whether SPF/DKIM passed. The raw XML is hard to read—use a free parser like Postmark DMARC or dmarcian to turn them into readable dashboards. You'll quickly spot unauthorized senders this way.

What is DMARC alignment and should I use strict or relaxed?

Alignment checks whether the domain in SPF/DKIM matches the From header domain. Relaxed (adkim=r, aspf=r) allows subdomains to match—mail.example.com passes for example.com. Strict (adkim=s, aspf=s) requires an exact match. Start with relaxed. Switch to strict only after you've confirmed all your sending services align properly.

What is the percentage (pct) field for?

The pct field lets you apply your policy to only a fraction of failing emails. Setting pct=10 with p=quarantine means only 10% of failing emails go to spam—the rest are treated as if you had p=none. It's your safety net when transitioning policies. Increase by 10-25% every week as you gain confidence.

Will DMARC break my transactional emails?

It can, if you skip the monitoring phase. Transactional services like SendGrid, Postmark, or Amazon SES need DKIM signing configured and need to be included in your SPF record. The p=none phase is specifically designed to catch these gaps before you enforce. Check your reports carefully for any failing legitimate sources.

How long does it take for a DMARC record to take effect?

DNS propagation typically takes 1-48 hours, but most providers pick up changes within a few hours. Aggregate reports start arriving within 24-48 hours of publishing your record. Use a DNS propagation checker to confirm your record is live before waiting for reports.

Compare email marketing software

Hands-on roundups to help you pick the right platform.