DMARC Record Generator

DMARC Record Generator

Pick a policy, add a mailbox for aggregate reports and this page writes the DMARC record for you, including the underscore host name you publish it on.

How to use

  1. Enter your domain and start with policy none so you observe before you enforce.
  2. Add a mailbox that can receive aggregate XML reports. A shared inbox or a reporting service both work.
  3. Optionally tighten alignment or lower the percentage while you roll out.
  4. Publish the value as a TXT record on _dmarc.yourdomain, then read the reports for a couple of weeks before moving to quarantine or reject.

Frequently asked questions

Where exactly does the record go?
On the host _dmarc under your domain, so the full name is _dmarc.example.com. Publishing it on the root will not work.
Do I need forensic reports?
Rarely. Most providers do not send them and they can contain message content, so many teams publish only rua.
How fast should I go to reject?
Sit at none until your aggregate reports show every legitimate source passing SPF or DKIM with alignment. Then quarantine, then reject. Weeks, not hours.