Interactive Tool

DMARC record generator

Build a DMARC record the way it's actually meant to be deployed — starting at p=none so you can watch what's happening before you enforce anything, not jumping straight to reject and hoping for the best.

This tool runs entirely in your browser. Nothing you enter is sent anywhere — it's just building a text record from the options you choose. No analytics, no tracking, no calls back to our servers.

DMARC tells receiving mail servers what to do with messages that fail SPF and DKIM checks, and optionally sends you reports on who's sending mail claiming to be from your domain — including, often, mail you didn't know was going out. A DMARC record is not a set-and-forget line you paste in once at full enforcement. It's a graduated rollout, and this tool defaults to the first, safest step. For how DMARC fits with SPF and DKIM, see SPF, DKIM and DMARC explained.

The three-step progression

1

p=none

Start here. Nothing is blocked. You just start receiving reports on what's actually sending mail as your domain.

2

p=quarantine

Once reports look clean, failing mail gets sent to spam/junk instead of being delivered normally.

3

p=reject

Failing mail is rejected outright. Only move here once quarantine has run clean for a genuine stretch of time.

1. Your domain

Used only to show you the DNS record name — it isn't sent anywhere.

2. Policy

3. Reporting addresses

Daily summaries of who's sending mail as your domain and whether it passed. Strongly recommended even at p=none — without this you're monitoring blind. You can enter multiple addresses separated by commas.

Per-message failure reports. Increasingly few mailbox providers actually send these due to privacy concerns, so most setups rely on rua alone — leave this blank unless you specifically need it.

4. Your record

Add this as a TXT record at: _dmarc.yourdomain.com.au
v=DMARC1; p=none;

What to actually do at p=none

Once the record is live, wait — reports take a day or so to start arriving, and you want at least one to two weeks of them before drawing conclusions. When they do:

  • Read the aggregate (rua) reports for every source sending mail as your domain, not just the ones you recognise. This is often how businesses discover a forgotten marketing tool, an old CRM integration, or a third-party service still sending as their domain.
  • Confirm every legitimate source passes SPF or DKIM (DMARC only needs one of the two to align, not both). Anything legitimate that's failing needs fixing at the source — adding it to your SPF record, or setting up DKIM signing for it — before you tighten the policy.
  • Only move to p=quarantine once every legitimate sender is passing consistently. If something legitimate is still failing when you tighten the policy, quarantine will start sending real mail to spam.

The honest timeline: most businesses that do this properly spend a few weeks at p=none, a similar stretch at p=quarantine, and only then move to p=reject. Rushing this is the single most common way DMARC rollouts go wrong — not the record syntax, the pace.

Want to check what's actually live on your domain right now? Our DNS record checker looks up your current SPF, DMARC, and DKIM records and flags common problems, including a permissive policy with no reporting address.

Check my DNS →