DMARC Record Generator
Build a correct DMARC record, and a safe path from monitoring to p=reject.
Your settings
The record is published at _dmarc. followed by this domain. An e-mail address or a link works too.
Subdomains and alignment
adkim) aspf) Relaxed lets mail signed or sent by a subdomain of the same organization pass (news.example.com for example.com); strict needs the exact From domain. Keep relaxed unless you know why you need strict.
Advanced: psd and the historic pct
psd=n lets a department’s subdomain set policy for the names below it. psd=y is only for operators of endings such as .bank.
RFC 9989 replaced it with t: pct=0 corresponds to t=y and pct=100 to the default.
Start from your current record
Your DMARC record
- Type
TXT- Name / host
-
_dmarcFull name:_dmarc.<your domain> - Value
-
v=DMARC1; p=none
Authorisation for report addresses on other domains
The owner of each domain below must publish this TXT record, or receivers will not send it your reports (RFC 9990 §4). DMARC report services usually do this for all customers.
Companion records for a domain that never sends email
Zone-file lines
Every tag explained
Values in brackets are defaults that are not written into the record.
From monitoring to enforcement
Move one step at a time, only when the aggregate reports show that your own mail passes. Each step’s record keeps your report addresses and alignment settings.
About the DMARC Record Generator
DMARC tells mail servers what to do with messages that use your domain in the From address but fail authentication — deliver them anyway (p=none), put them in spam (p=quarantine) or refuse them (p=reject) — and where to send reports about who is sending as you. It is a single DNS TXT record at _dmarc.yourdomain, but its tags are easy to get wrong.
This generator builds the record from plain choices and follows RFC 9989, the DMARC standard that replaced RFC 7489: it writes only the tags you need, uses the testing flag t=y where the old pct would have gone, checks report addresses and works out the authorisation record that an address on another domain needs. Every tag is explained, and a five-step plan takes you from monitoring to enforcement with a ready record for each step. It can also read your current record back into the form, and add the companion records for a domain that never sends email.
How to use it
- Enter the domain in your From addresses. Tick This domain never sends email for a parked or website-only domain.
- Choose the policy. New to DMARC? Start with none and add a mailbox for aggregate reports (
rua). - Optionally set failure reports, a different policy for subdomains, strict alignment, or load your current record under Start from your current record.
- Copy the Name / host and Value into your DNS provider as a TXT record (or copy the zone-file lines), and publish any authorisation or companion records listed.
- Read the reports for a few weeks, then follow From monitoring to enforcement one step at a time.
Examples
Domain example.com · policy none · reports to dmarc-feedback@example.com
Name: _dmarc.example.com Value: v=DMARC1; p=none; rua=mailto:dmarc-feedback@example.com
Domain example.com · reports to reports@dmarc.example.net
v=DMARC1; p=none; rua=mailto:reports@dmarc.example.net The service must publish: example.com._report._dmarc.dmarc.example.net TXT "v=DMARC1;"
RFC 9990 §4: without that record, receivers do not send reports to an address outside your organizational domain.
Domain example.com · never sends email · reports to rua@example.net
v=DMARC1; p=reject; rua=mailto:rua@example.net plus: example.com TXT "v=spf1 -all", *._domainkey.example.com TXT "v=DKIM1; p=", example.com MX 0 .
The companion records follow M3AAWG’s best practices for parked domains.
Common uses
- Setting up DMARC for the first time, as Gmail and Yahoo require for bulk senders.
- Moving an existing
p=nonerecord to quarantine and reject without guessing the syntax. - Protecting parked, old or website-only domains that scammers could otherwise send from.
- Pointing reports to a DMARC report service and checking which authorisation record it needs.
What the tags do
v=DMARC1— required, and must come first.p— the policy for the domain (and its subdomains unlessspornpsay otherwise):none,quarantineorreject.sp— the policy for subdomains that exist;np— for subdomains that do not exist in DNS (made-up names a spoofer invents). Both work only in the record of an organizational domain.t=y— testing: receivers are asked to apply one level less (reject → quarantine, quarantine → none). It replacespct=0.rua— where daily aggregate reports go;ruf— where failure reports about single messages go;fo— when failure reports are generated.adkim,aspf— relaxed (default) or strict alignment between the From domain and the DKIM or SPF domain.psd— for public suffix operators (y), or to make a subdomain an organizational domain of its own (n).
RFC 9989 removed pct, rf and ri. Receivers that follow RFC 9989 ignore them; the generator writes pct only if you ask for it, for receivers that still follow RFC 7489. The tag definitions are in RFC 9989 §4.7.
Getting to p=reject safely
DMARC passes when a message passes SPF or DKIM and that domain aligns with the From domain. Before you enforce, every service that sends as you — your mailbox provider, newsletter tool, invoicing, CRM, help desk — must pass that way, and the aggregate reports are how you find them (RFC 9989 §5.1).
RFC 9989 §7.4 adds two warnings for p=reject: forwarding breaks SPF, so a domain that rejects must sign all its mail with DKIM; and domains whose people write to mailing lists should not publish p=reject — or should first run p=none for at least a month, then p=quarantine for as long, and compare. M3AAWG’s best practices recommend p=reject where possible and p=quarantine otherwise, with p=none only as a stage on the way.
Report addresses on another domain
Receivers send reports to an address outside your organizational domain only if that domain agrees, by publishing a TXT record named your-domain._report._dmarc.their-domain that contains v=DMARC1; (RFC 9990 §4). DMARC report services publish these for their customers (often for any domain at once, with a wildcard). For a second domain of your own, add the record yourself — the generator shows the exact name.
Limitations
- It builds the record but does not look anything up: check the published record afterwards with the DMARC Record Checker, and SPF and DKIM with their checkers.
- Whether a report address is “on another domain” is judged with the Public Suffix List. Receivers that follow RFC 9989 find organizational domains with a DNS tree walk, which can differ for domains that publish psd tags.
- DMARC protects the exact From domain only. Look-alike domains (examp1e.com) need their own monitoring.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Do Gmail and Yahoo require DMARC?
For bulk senders, yes. Google’s sender guidelines ask senders of more than 5,000 messages a day to Gmail accounts to set up SPF, DKIM and DMARC, with a policy that can be none, and to align the From domain with SPF or DKIM. Yahoo’s sender requirements likewise ask bulk senders for at least p=none and recommend a rua address. Both urge every sender to publish DMARC.
Where exactly do I add the record?
At your DNS host (often your domain registrar or a separate DNS provider), add a TXT record. Most dashboards want only the host part, _dmarc, and add the domain themselves; some want the full name _dmarc.example.com. Paste the value without the surrounding quotes. Only one DMARC record may exist for a name: receivers ignore the name entirely if they find two.
Which policy should I start with?
p=none with a rua address. It changes nothing for your mail and shows, within a few days, which services send as your domain and whether they pass. Move on when the reports show your own mail passing.
What is the difference between rua and ruf?
rua gets aggregate reports: usually one XML file a day from each receiver that sends them, with counts per sending server and their SPF, DKIM and DMARC results — no message content. ruf gets failure reports about single messages, which can include headers or content; few large providers send them, so they are optional.
Should I use t=y or pct?
Use t=y: it is the testing flag of RFC 9989, which removed pct because values other than 0 and 100 were applied inconsistently. If some of your recipients’ servers still follow RFC 7489, you can add pct=0 alongside t=y under Advanced — the two mean the same.
Do subdomains need their own record?
Usually not: subdomains follow the record of your organizational domain, using its sp (existing subdomains) or np (non-existent ones), else p. Publish a separate record only for a subdomain that needs a different policy or report address — and add psd=n to it if the names below that subdomain should follow it too.