Founder price · 100 spots leftReserve

[ Free tool ]

DMARC record generator

Build a DMARC record for your domain under the current standard (RFC 9989): policy, test mode, reports and alignment, with a safe path from none to reject.

· 5 min read

[ In short ]

  • A DMARC record is a TXT record at _dmarc.example.com, like v=DMARC1; p=none; rua=mailto:dmarc@example.com.
  • DMARC is now RFC 9989 (May 2026): it adds np and t, and drops pct, rf and ri. Old records still work.
  • Start at p=none with a report address, then move to quarantine and reject once every real sender passes.
  • To test a stricter policy, use t=y, and add pct=0 for receivers that still follow the old RFC 7489.

01Build your DMARC record

Enter your domain and an address for aggregate reports, pick a policy, and copy the record. The advanced options cover subdomains, failure reports and alignment. Underneath, the rollout shows where your record stands on the way to reject.

Policy for failing mail (p)

Monitor only: deliver as usual and send reports.

Subdomains, failure reports, alignment
Existing subdomains (sp)
Subdomains that do not exist (np)
DKIM alignment (adkim)
SPF alignment (aspf)
Your DMARC record
Type
TXT
Host
_dmarc
Value
v=DMARC1; p=none

Checks

  • Warning: No aggregate report address (rua). Without reports you cannot see who sends as your domain, so you cannot move past p=none safely.
Rollout: where this record stands
  1. p=noneyou are hereWeeks 1–4: read the reports, fix every sender that fails.
  2. p=quarantine; t=yTest: receivers apply none, and you see what quarantine would catch.
  3. p=quarantineA few weeks with no legitimate mail in the failing column.
  4. p=rejectThe goal: spoofed mail is refused outright.

Runs in your browser. Nothing you type is sent anywhere.

Tags equal to their default are left out, so the record stays short and readable.

02What a DMARC record does

DMARC ties the address people see in the From line to the checks receivers already run. A message passes when SPF or DKIM passes for a domain that aligns with the From domain. Your record tells receivers what to do with mail that fails, and where to send reports about all the mail they saw from your domain.

Since February 2024, Gmail and Yahoo require a DMARC record from anyone sending more than about 5,000 messages a day to their users, and p=none is enough to meet that rule. The details are in Gmail and Yahoo sender requirements.

TXT record at _dmarc.example.com
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com

03DMARC tags under RFC 9989

RFC 9989 replaced RFC 7489 in May 2026, with reporting split into RFC 9990 (aggregate) and RFC 9991 (failure). Receivers must ignore tags they do not know, so records written for either version keep working.

TagWhat it setsDefault
vAlways DMARC1, and always first.required
pPolicy for mail that fails: none, quarantine or reject.none
spPolicy for subdomains that exist.same as p
npNew: policy for subdomains that do not exist, a common spoofing trick.same as sp
tNew: t=y asks receivers to apply one step softer while you test.n
ruaWhere aggregate reports go (mailto: addresses).none
rufWhere failure reports go, if receivers send them.none
adkim / aspfAlignment: r (same organizational domain) or s (exact).r
pct, rf, riRemoved. pct is replaced by t; rf and ri were rarely used.gone

Test mode and older receivers

Under the old standard, pct=0 asked receivers to apply the next softer policy to all mail. RFC 9989 replaces it with t=y, which asks for the same thing. While receivers move from one standard to the other, a record in test mode can carry both: new receivers read t and ignore pct, old ones read pct and ignore t. When you leave test mode, remove both.

Testing quarantine
v=DMARC1; p=quarantine; t=y; pct=0; rua=mailto:dmarc@example.com

04The rollout: from none to reject

  1. p=none with rua. Read the reports for two to four weeks. Every service that sends as you appears, including ones nobody remembered (billing, helpdesk, the CRM).
  2. Fix each legitimate sender: add it to SPF, or better, turn on DKIM signing with your domain in that service.
  3. p=quarantine with t=y (and pct=0). Receivers still apply none, but you learn what quarantine would catch.
  4. p=quarantine. Failing mail goes to spam. Watch the reports for a few weeks.
  5. p=reject. Spoofed mail is refused outright. Keep reading the reports: new tools get added.

Moving fast is how teams lose invoices and password resets to the spam folder. Each step only once the reports show no legitimate mail failing.

05Reading the reports

Aggregate reports are XML files that receivers send once a day or so: which servers sent mail as your domain, how many messages, and whether SPF, DKIM and alignment passed. They are hard to read raw. A free or paid DMARC report service turns them into a list of senders.

  • If example.com sends its reports to another domain, such as a report service at example.net, that domain must publish a TXT record at example.com._report._dmarc.example.net with v=DMARC1, or receivers will not send them (RFC 9990). Most services set this up for you.
  • Failure reports (ruf) are rare: most large mailbox providers do not send them, and the ones that arrive can contain parts of messages, which is personal data under the GDPR.
  • Use a dedicated address for reports. At reject, a busy domain can get dozens a day.

06Common DMARC mistakes

  • Publishing at the domain itself instead of at _dmarc. The host must be _dmarc (or _dmarc.example.com).
  • Staying at p=none forever. It satisfies the bulk-sender rules but protects nothing.
  • Jumping to reject before checking reports, and losing legitimate mail from a forgotten tool.
  • Strict alignment (s) with services that bounce or sign from a subdomain; they then fail.
  • Keeping pct=50 or similar from an old guide. RFC 9989 drops partial enforcement; use t=y to test instead.
  • Two DMARC records at _dmarc. Like SPF, there must be only one.

Business email on your own domain with an agent that follows up on every conversation. Hosted in the EU. On supported DNS providers it writes your domain’s records for you. See it in the demo.

Questions

Is pct still supported in DMARC?
RFC 9989 removed it and added t (test mode) instead. Receivers that still follow RFC 7489 understand pct, and receivers must ignore tags they do not know, so an old record keeps working. For testing, publish t=y and pct=0 together.
What is the np tag in DMARC?
np sets the policy for subdomains that do not exist, such as invoices.example.com when you never created it. Attackers use made-up subdomains because sp only covers subdomains that exist. If you leave np out, it inherits sp, then p.
Is p=none enough?
It meets Gmail and Yahoo’s requirement for bulk senders and gets you reports, but it does not stop spoofing. Treat it as the first step of the rollout, then move to quarantine and reject.
Do I need SPF and DKIM before DMARC?
You can publish DMARC at p=none first to see who sends as you. Before quarantine or reject, every legitimate sender needs SPF or DKIM passing and aligned with your domain, ideally DKIM.
Where do I put the DMARC record?
In a TXT record with the host _dmarc (in most DNS panels) or _dmarc.example.com (fully qualified). The value starts with v=DMARC1.

See Skein follow up for you

Business email on your own domain with an agent that follows up on every conversation. Hosted in the EU. Try the demo with sample mail, nothing to install.

[ Sources ]

  1. 01RFC 9989: Domain-based Message Authentication, Reporting, and Conformance (DMARC)
  2. 02RFC 9990: DMARC aggregate reporting
  3. 03RFC 7489: DMARC (obsoleted by RFC 9989)
  4. 04Google: Email sender guidelines
  5. 05dmarcian: DMARC RFC updates

Facts about other products were checked on 5 Oct 2026; prices and plans change.

[ Read next ]