100% Free • No Signup • Live DNS

DMARC Checker

Check your DMARC record, validate policy settings, review reporting addresses and find email authentication issues.

Free DMARC lookup • No signup • Live DNS

Why DMARC matters

DMARC tells receiving mail servers what to do when SPF or DKIM fail — and whether messages truly come from your domain. A missing record, monitoring-only policy or misconfigured reporting can leave your brand open to spoofing and weaken the protection SPF and DKIM provide together.

What this checker validates

One check reviews your DMARC record, policy, reporting addresses and alignment settings.

DMARC record presence

  • TXT at _dmarc.domain
  • v=DMARC1 version tag
  • Single record check
  • Host naming validation

Find the DMARC TXT record published at _dmarc.yourdomain.com.

Policy mode

  • p=none monitoring
  • p=quarantine enforcement
  • p=reject enforcement
  • Policy syntax validation

Review whether your policy is none, quarantine or reject.

Subdomain policy

  • sp= tag detection
  • Subdomain vs org policy
  • Missing sp= fallback
  • Policy mismatch flag

Check whether a separate subdomain policy is configured.

Reporting addresses

  • rua aggregate reports
  • ruf forensic reports
  • mailto: URI validation
  • External report domains

Check aggregate and forensic reporting addresses using rua and ruf.

Alignment policy

  • adkim strict/relaxed
  • aspf strict/relaxed
  • Alignment mode review
  • SPF/DKIM dependency hint

Validate adkim and aspf alignment settings for SPF and DKIM.

Syntax & tag validation

  • Tag formatting rules
  • pct percentage check
  • Invalid tag detection
  • Record length review

Validate DMARC tag syntax and overall record formatting.

Common DMARC issues this tool can detect

Find configuration problems that may affect domain protection and email authentication visibility.

Missing & duplicate records

  • DMARC record missing
  • Multiple DMARC records found
  • Record at wrong DNS host

Syntax & invalid tags

  • DMARC syntax invalid
  • Record syntax errors
  • Malformed tag values

Policy & enforcement

  • Policy is monitoring only
  • pct tag not set to 100
  • Weak subdomain policy

Reporting & external auth

  • No aggregate reporting address
  • Invalid reporting URI
  • External domain not authorized

Pair with SPF and DKIM for complete email authentication coverage.

How DMARC checking works

The checker reads your DMARC TXT record and explains your policy in plain language.

  1. Enter your domain

    We normalize the domain and locate the _dmarc TXT record in public DNS.

  2. Query _dmarc DNS record

    The tool checks TXT records at _dmarc.yourdomain.com.

  3. Analyze policy and reports

    We validate syntax, policy, reporting addresses, alignment and recommended improvements.

When to check DMARC

  • Before enabling BIMI logo display
  • After changing email providers
  • Before moving to quarantine or reject
  • During domain migration
  • After SPF or DKIM changes
  • Periodic compliance review

Understanding DMARC policies

p=none

Monitoring — Valid DMARC policy used to collect reports. It does not block or quarantine unauthenticated email.

p=quarantine

Quarantine — Tells receivers to treat failing messages as suspicious, often placing them in spam or quarantine.

p=reject

Reject — Strongest DMARC policy. Tells receivers to reject messages that fail DMARC authentication.

pct

Policy percentage — Controls what percentage of email is subject to the DMARC policy. Full enforcement usually uses pct=100.

DMARC should normally be deployed gradually: monitor first, then move to quarantine or reject after confirming legitimate senders are aligned.

Preparing DMARC check…

Need help fixing DMARC?

Send us your domain report and we’ll review the issue.

Get Help

DMARC analysis reflects your published policy. Enforcement depends on receiving mail servers. How we check

Frequently asked questions

A DMARC record is a DNS TXT record that tells receiving mail servers what to do when email fails SPF or DKIM authentication and alignment checks.
A DMARC record is published as a TXT record at _dmarc.yourdomain.com.
No. p=none is valid and useful for monitoring. However, it does not enforce protection against unauthenticated email.
For strong protection, p=reject is usually the strongest policy. However, domains should usually start with p=none, review reports, then move gradually to quarantine or reject.
rua defines the email address or destination where aggregate DMARC reports are sent.
No. The DMARC Checker is free and does not require signup.