Look up, validate, and debug the DMARC record on any domain. Policy check, alignment hints, aggregate reporting verification.
This tool resolves the DMARC TXT record at _dmarc.<your-domain>, parses every tag, and identifies common configuration problems that leave domains vulnerable to spoofing or unable to receive aggregate reports.
DMARC is not a "publish once and forget" record. The correct rollout takes 90 days minimum:
Our full email authentication walkthrough covers alignment rules, multi-provider setup, common mistakes, and verification commands.
Read the full guidep=none is monitor-only. Receiving servers send you reports but still deliver spoofed mail to your customers. After 30 days of clean reports (every legitimate sender aligned), ramp to p=quarantine, then p=reject.
Daily XML files from every mailbox provider, one per provider. Each contains a count of mail authenticated against your domain, broken down by source IP, SPF result, DKIM result, and alignment outcome. Parse these with a free tool like Postmark DMARC or pay for Valimail/dmarcian for dashboards.
Strict only if you control all subdomain sending and never want subdomain.example.com to authenticate as example.com. For most senders, relaxed alignment (the default) is correct and lower-risk.
Yes, but it does nothing useful. DMARC requires at least one of SPF or DKIM to pass with alignment. Publish both first, confirm they pass alignment, then publish DMARC.