DMARC checker: check your DMARC policy

Check that your DMARC record is valid, see your policy and report addresses, and learn what to change next.

Enter a domain name or an email address, then run the check. Results appear after the form and are announced when they finish.

Reads public DNS records only.

How it works

Check your DMARC policy in seconds

See whether your domain is protected against fake email, and what to change next.

Enter your domain

Type the domain in your From address, or any email address at that domain.

We read every tag

The checker finds the record at _dmarc.yourdomain, or at your main domain for subdomains, and reads every tag.

See your next step

You see your policy, report addresses and alignment, and what to change to protect your domain further.

The three policies

From monitoring to full protection

p=none

Monitoring only. Fake email is still delivered, but you receive reports about it. The right place to start.

p=quarantine

Email that fails is sent to spam. Use it once your reports show your own email passes.

p=reject

Email that fails is refused. The strongest protection, and required for BIMI logos alongside quarantine.

Good to know

Moving to a strict policy safely

01

Add a report address

Without rua=, you cannot see who sends email as your domain. Use a mailbox or a DMARC report service.

02

Watch the reports for a few weeks

Make sure every service that sends for you passes SPF or DKIM with your domain.

03

Step up gradually

Move from none to quarantine, optionally with pct= to apply it to part of your email first, then to reject.

More email tools

Check the rest of your email setup

Domain scanner

SPF, DKIM, DMARC, BIMI, mail servers and blocklists in one scan.

SPF checker

Check your SPF record, its includes and the 10-lookup limit.

DKIM checker

Find your DKIM keys and check their length and format.

BIMI checker

Check your logo record, SVG file and certificate.

Mail tester

Send one email and get a spam score out of 10.

Questions

DMARC, explained

Something else? Get in touch and we’ll answer.

DMARC tells receiving servers what to do with email that claims to come from your domain but fails SPF and DKIM: deliver it, send it to spam or reject it. It also sends you reports about who is sending as your domain.

Start with p=none and a rua= report address. Read the reports for a few weeks to confirm your own email passes, then move to p=quarantine and finally p=reject.

rua= is the address that receives daily summary reports. ruf= receives reports about single failed messages; few providers send those.

Gmail, Yahoo and Microsoft require a DMARC record from anyone who sends bulk email to their users. For everyone else it is strongly recommended.

Try it

Is your domain protected from fake email?

Check your DMARC record and see your next step.