Free tool · RFC 9989
DMARC record generator
Choose a policy and a report address: this DMARC generator writes the record as you type and shows the exact name and value to add at your DNS host.
Your DMARC record
_dmarc.example.com TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
Where to add the DMARC record
Add the record at the company that runs DNS for your domain: your registrar, Cloudflare, or your web host. Every DNS host asks for the same three things, under different field names:
| DNS host | Name field | Enter | Value field | Note |
|---|---|---|---|---|
| Cloudflare | Name | _dmarc | Content | |
| GoDaddy | Name | _dmarc | Value | |
| Namecheap | Host | _dmarc | Value | Leave out your domain: Namecheap adds it. |
| Squarespace Domains (formerly Google Domains) | Name | _dmarc | Data | |
| Amazon Route 53 | Record name | _dmarc | Value | Put the value in double quotes. |
Choose TXT as the record type. If you type _dmarc.example.com into a field that adds the domain by itself, you end up with _dmarc.example.com.example.com, and receivers will not find the record. One domain can have only one DMARC record: edit the existing one instead of adding a second.
Which policy to start with: none, quarantine, reject
DMARC tells receivers what to do with mail that claims to come from your domain but fails authentication. Moving straight to reject is how companies block their own invoices, so roll it out in three steps:
Step 1 · p=none
Monitor
Nothing changes for your mail. Daily reports show every server that sends as your domain. Fix SPF and DKIM for each legitimate sender.
Step 2 · p=quarantine
Spam folder
Once only unknown or spoofed sources fail, switch to quarantine: failing mail then goes to spam. Mistakes are still recoverable.
Step 3 · p=reject
Full protection
Receivers refuse mail that fails DMARC. Keep reading reports: a new tool that sends as you must be set up first.
How long each step takes depends on how many services send as your domain. A small company with one mailbox provider and one newsletter tool can move in weeks; an organization with dozens of SaaS senders often needs months at p=none.
What to look for in the reports before each move:
- Every source you recognize passes SPF or DKIM with alignment, meaning the authenticated domain matches your From domain.
- The sources that fail are ones you don’t recognize or that your company never sends from. That is spoofing, and it is what DMARC is for.
- Forwarded mail (mailing lists, auto-forwards) can fail SPF. DKIM usually survives plain forwarding (mailing lists that change the message can break it), so make sure your senders sign with DKIM.
DMARC record examples
; 1. Monitoring: no effect on delivery, daily reports
_dmarc.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
; 2. Quarantine, with a stricter policy for subdomains that don't exist
_dmarc.example.com. TXT "v=DMARC1; p=quarantine; np=reject; rua=mailto:dmarc-reports@example.com"
; 3. Reject, with reports sent to a DMARC report service
_dmarc.example.com. TXT "v=DMARC1; p=reject; rua=mailto:dmarc@reports.example.net"
; 4. A domain that never sends email
_dmarc.example.com. TXT "v=DMARC1; p=reject"
A domain that sends no email at all should also publish v=spf1 -all as its SPF record, so it cannot be used for spoofing.
When reports go to another domain, as in example 3, receivers send them only if that domain agrees: it publishes a TXT record v=DMARC1 at example.com._report._dmarc.reports.example.net (RFC 9990). DMARC report services set this up for their customers.
DMARC tags (RFC 9989)
In May 2026, RFC 9989 replaced RFC 7489 as the DMARC standard. Records written for the old standard keep working; the changes are in the optional tags.
| Tag | Values | Default | What it does |
|---|---|---|---|
v | DMARC1 | required | Version. Must be the first tag. |
p | none, quarantine, reject | Policy for mail that fails DMARC. | |
sp | none, quarantine, reject | value of p | Policy for subdomains. |
np | none, quarantine, reject | value of sp | Policy for subdomains that don’t exist in DNS. New in RFC 9989 (previously RFC 9091). |
t | y, n | n | Testing mode: receivers apply one level less than the policy. New in RFC 9989; replaces pct. |
rua | mailto: addresses | none | Where aggregate reports go. |
ruf | mailto: addresses | none | Where failure reports on single messages go. |
fo | 0, 1, d, s | 0 | When to send failure reports. Only used with ruf. |
adkim | r, s | r | DKIM alignment: relaxed accepts subdomains, strict needs an exact match. |
aspf | r, s | r | SPF alignment, as above. |
psd | y, n, u | u | For public suffix operators such as registries. Ordinary domains leave it out. |
Removed in RFC 9989: pct (apply the policy to a share of mail), rf (report format) and ri (report interval). Receivers that follow the new standard ignore them, and the generator does not write them.
DMARC and the Gmail, Yahoo and Microsoft sender rules
Since February 2024, Gmail and Yahoo require a DMARC record from bulk senders. Gmail counts senders of close to 5,000 or more messages a day to personal Gmail accounts; Yahoo sets no number. p=none is enough, but the From domain must align with SPF or DKIM. Since May 5, 2025, Microsoft has applied the same rule to Outlook.com, Hotmail.com and Live.com; mail that fails it can be rejected with 550 5.7.515 Access denied, sending domain … does not meet the required authentication level. The full checklist is in our guide to Gmail and Yahoo sender requirements.
Check your record
After publishing, run the DMARC checker on your domain: it shows the policy receivers see and flags missing report addresses. Check the two records DMARC depends on with the SPF checker and the DKIM checker, or build the SPF record with the SPF record generator.
Mail rejected under your DMARC policy comes back to the sender with a bounce such as 550 5.7.26 at Gmail or 550 5.7.509 at Microsoft 365. The SMTP error codes reference explains those messages.
Frequently asked questions
What is a DMARC record?
Which DMARC policy should I use?
Do I need SPF and DKIM before DMARC?
Where do I add the DMARC record?
How long until DMARC works?
Is the pct tag still valid?
Email validation API
Validate emails in your app
emailvalidation.io checks syntax, MX records and the mailbox over SMTP, flags disposable, role and free addresses and returns a quality score, in one request.
/v1/info Email validation API Read the documentation
100 free validations every month. No credit card required.
GET https://api.emailvalidation.io/v1/info?
{
"email": "support@emailvalidation.io",
"user": "support",
"tag": "",
"domain": "emailvalidation.io",
"format_valid": true,
"mx_found": true,
"smtp_check": true,
"catch_all": null,
"role": true,
"disposable": false,
"free": false,
"score": 0.64,
"state": "deliverable",
"reason": "valid_mailbox",
"did_you_mean": ""
}