Free tool · RFC 9989

DMARC record generator

Choose a policy and a report address: this DMARC generator writes the record as you type and shows the exact name and value to add at your DNS host.

Used for the record name and to check where your reports go. Optional.

Policy for mail that fails DMARC

Receivers send daily XML reports about everyone who sends mail as your domain. Use a mailbox you created for this or the address of a DMARC report service. Separate several addresses with commas.

More options

Optional. Reports on single failing messages. Few receivers send them.

The record is built in your browser. Nothing you type here is sent to us.

Your DMARC record

_dmarc.example.com  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

Where to add the DMARC record

Add the record at the company that runs DNS for your domain: your registrar, Cloudflare, or your web host. Every DNS host asks for the same three things, under different field names:

DNS hostName fieldEnterValue fieldNote
CloudflareName_dmarcContent
GoDaddyName_dmarcValue
NamecheapHost_dmarcValueLeave out your domain: Namecheap adds it.
Squarespace Domains (formerly Google Domains)Name_dmarcData
Amazon Route 53Record name_dmarcValuePut the value in double quotes.

Choose TXT as the record type. If you type _dmarc.example.com into a field that adds the domain by itself, you end up with _dmarc.example.com.example.com, and receivers will not find the record. One domain can have only one DMARC record: edit the existing one instead of adding a second.

Which policy to start with: none, quarantine, reject

DMARC tells receivers what to do with mail that claims to come from your domain but fails authentication. Moving straight to reject is how companies block their own invoices, so roll it out in three steps:

Step 1 · p=none

Monitor

Nothing changes for your mail. Daily reports show every server that sends as your domain. Fix SPF and DKIM for each legitimate sender.

Step 2 · p=quarantine

Spam folder

Once only unknown or spoofed sources fail, switch to quarantine: failing mail then goes to spam. Mistakes are still recoverable.

Step 3 · p=reject

Full protection

Receivers refuse mail that fails DMARC. Keep reading reports: a new tool that sends as you must be set up first.

How long each step takes depends on how many services send as your domain. A small company with one mailbox provider and one newsletter tool can move in weeks; an organization with dozens of SaaS senders often needs months at p=none.

What to look for in the reports before each move:

  1. Every source you recognize passes SPF or DKIM with alignment, meaning the authenticated domain matches your From domain.
  2. The sources that fail are ones you don’t recognize or that your company never sends from. That is spoofing, and it is what DMARC is for.
  3. Forwarded mail (mailing lists, auto-forwards) can fail SPF. DKIM usually survives plain forwarding (mailing lists that change the message can break it), so make sure your senders sign with DKIM.

DMARC record examples

; 1. Monitoring: no effect on delivery, daily reports
_dmarc.example.com.  TXT  "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"

; 2. Quarantine, with a stricter policy for subdomains that don't exist
_dmarc.example.com.  TXT  "v=DMARC1; p=quarantine; np=reject; rua=mailto:dmarc-reports@example.com"

; 3. Reject, with reports sent to a DMARC report service
_dmarc.example.com.  TXT  "v=DMARC1; p=reject; rua=mailto:dmarc@reports.example.net"

; 4. A domain that never sends email
_dmarc.example.com.  TXT  "v=DMARC1; p=reject"

A domain that sends no email at all should also publish v=spf1 -all as its SPF record, so it cannot be used for spoofing.

When reports go to another domain, as in example 3, receivers send them only if that domain agrees: it publishes a TXT record v=DMARC1 at example.com._report._dmarc.reports.example.net (RFC 9990). DMARC report services set this up for their customers.

DMARC tags (RFC 9989)

In May 2026, RFC 9989 replaced RFC 7489 as the DMARC standard. Records written for the old standard keep working; the changes are in the optional tags.

TagValuesDefaultWhat it does
vDMARC1requiredVersion. Must be the first tag.
pnone, quarantine, rejectPolicy for mail that fails DMARC.
spnone, quarantine, rejectvalue of pPolicy for subdomains.
npnone, quarantine, rejectvalue of spPolicy for subdomains that don’t exist in DNS. New in RFC 9989 (previously RFC 9091).
ty, nnTesting mode: receivers apply one level less than the policy. New in RFC 9989; replaces pct.
ruamailto: addressesnoneWhere aggregate reports go.
rufmailto: addressesnoneWhere failure reports on single messages go.
fo0, 1, d, s0When to send failure reports. Only used with ruf.
adkimr, srDKIM alignment: relaxed accepts subdomains, strict needs an exact match.
aspfr, srSPF alignment, as above.
psdy, n, uuFor public suffix operators such as registries. Ordinary domains leave it out.

Removed in RFC 9989: pct (apply the policy to a share of mail), rf (report format) and ri (report interval). Receivers that follow the new standard ignore them, and the generator does not write them.

DMARC and the Gmail, Yahoo and Microsoft sender rules

Since February 2024, Gmail and Yahoo require a DMARC record from bulk senders. Gmail counts senders of close to 5,000 or more messages a day to personal Gmail accounts; Yahoo sets no number. p=none is enough, but the From domain must align with SPF or DKIM. Since May 5, 2025, Microsoft has applied the same rule to Outlook.com, Hotmail.com and Live.com; mail that fails it can be rejected with 550 5.7.515 Access denied, sending domain … does not meet the required authentication level. The full checklist is in our guide to Gmail and Yahoo sender requirements.

Check your record

After publishing, run the DMARC checker on your domain: it shows the policy receivers see and flags missing report addresses. Check the two records DMARC depends on with the SPF checker and the DKIM checker, or build the SPF record with the SPF record generator.

Mail rejected under your DMARC policy comes back to the sender with a bounce such as 550 5.7.26 at Gmail or 550 5.7.509 at Microsoft 365. The SMTP error codes reference explains those messages.

Frequently asked questions

What is a DMARC record?

A TXT record at _dmarc.yourdomain.com. It tells receiving mail servers what to do with mail that shows your domain in the From address but fails SPF and DKIM alignment (deliver it, send it to spam or reject it), and where to send reports about that mail.

Which DMARC policy should I use?

Start with p=none and a report address. Read the reports, fix your own senders until they pass, then move to p=quarantine and finally p=reject. Going straight to reject can block your own invoices or newsletters if one sending service is not set up yet.

Do I need SPF and DKIM before DMARC?

A message passes DMARC when SPF or DKIM passes for a domain that matches the From address, so DMARC builds on both. You can publish p=none first: the reports then show which senders still lack SPF or DKIM. Set those up before you move to quarantine or reject. The SPF record generator and the DKIM checker help.

Where do I add the DMARC record?

At the DNS host of your domain, which is often your registrar, Cloudflare or your web host. Add a TXT record with the name _dmarc and the generated value. If your DNS host asks for the full name, enter _dmarc.example.com instead.

How long until DMARC works?

Receivers use the record as soon as DNS returns it, usually within an hour of publishing. Aggregate reports cover one day each, so the first ones arrive a day or two later.

Is the pct tag still valid?

RFC 9989, which replaced RFC 7489 in May 2026, removed pct along with rf and ri. For testing it adds t=y, which asks receivers to apply one level less than your policy. Receivers that still follow RFC 7489 keep honoring pct and ignore t=y, so test with p=none if you need certainty.

Email validation API

Validate emails in your app

emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.

/v1/info Email validation API Read the documentation

100 free validations every month. No credit card required.

GET https://api.emailvalidation.io/v1/info?email=support@emailvalidation.io

{
  "email": "support@emailvalidation.io",
  "user": "support",
  "tag": "",
  "domain": "emailvalidation.io",
  "format_valid": true,
  "mx_found": true,
  "smtp_check": true,
  "catch_all": null,
  "role": true,
  "disposable": false,
  "free": false,
  "score": 0.64,
  "state": "deliverable",
  "reason": "valid_mailbox",
  "did_you_mean": ""
}

Free email tools

Start using our email validation software today!

Get 100 validations per month for free