DMARC Record Generator
Pick a policy, add a mailbox for aggregate reports and this page writes the DMARC record for you, including the underscore host name you publish it on.
How to use
- Enter your domain and start with policy none so you observe before you enforce.
- Add a mailbox that can receive aggregate XML reports. A shared inbox or a reporting service both work.
- Optionally tighten alignment or lower the percentage while you roll out.
- Publish the value as a TXT record on _dmarc.yourdomain, then read the reports for a couple of weeks before moving to quarantine or reject.
Frequently asked questions
- Where exactly does the record go?
- On the host
_dmarcunder your domain, so the full name is_dmarc.example.com. Publishing it on the root will not work. - Do I need forensic reports?
- Rarely. Most providers do not send them and they can contain message content, so many teams publish only
rua. - How fast should I go to reject?
- Sit at none until your aggregate reports show every legitimate source passing SPF or DKIM with alignment. Then quarantine, then reject. Weeks, not hours.