DMARC Checker

Verify DMARC records to protect your domain from email spoofing

Share:

Check DMARC Record

Protect Your Domain with DMARC

DMARC authentication prevents email spoofing and phishing attacks on your domain

DMARC (Domain-based Message Authentication, Reporting & Conformance) is an email authentication protocol that builds on SPF and DKIM to protect your domain from unauthorized use. Our checker looks up and analyzes your DMARC record to verify proper configuration.

What This Tool Checks

DMARC Record Lookup

Queries DNS for your _dmarc TXT record and displays the full record.

Policy Analysis

Evaluates your DMARC policy (none, quarantine, reject) and recommends improvements.

Report Configuration

Verifies aggregate (rua) and forensic (ruf) reporting email addresses.

Tag Parsing

Breaks down all DMARC tags and explains their purpose.

Best Practices

  • Start with p=none to monitor before enforcing.
  • Always configure rua for aggregate reports.
  • Gradually move to p=quarantine then p=reject.
  • Ensure SPF and DKIM are properly configured first.
  • Use DMARC reporting services to analyze report data.
  • Set adkim and aspf alignment to strict when ready.

Frequently Asked Questions

What does DMARC p=none mean?

p=none means no action is taken on emails that fail authentication — you only receive reports. This is the monitoring phase, useful when first implementing DMARC.

How long does DMARC take to work?

DNS propagation takes up to 48 hours, but most changes apply within minutes. It's recommended to monitor with p=none for 2-4 weeks before enforcing.

Do I need SPF and DKIM for DMARC?

Yes, DMARC requires at least one of SPF or DKIM to be configured. For best results, implement both.