Free DMARC Record Generator - Build TXT with rua | BounceZero
Policy + Alignment + rua + Rollout Guidance

DMARC Record Generator

Build a valid DMARC TXT record with the right policy, reporting addresses, and alignment mode. Includes the 30-60-90 day rollout playbook.

100 = apply to all. Use 25/50/75 for gradual rollout to p=reject.
Comma-separated for multiple addresses. Use a parser like Postmark DMARC (free) or dmarcian to make reports readable.
Sends a forensic copy of every failed message. Most providers (including Google) do NOT send ruf reports for privacy reasons - rua is the primary signal.
Advanced options (failure reporting + interval)
Default 86400 (24h). Most receivers ignore this.

The 30-60-90 DMARC Rollout

DMARC is not a "publish once and forget" record. The correct rollout takes 90 days minimum to avoid blocking legitimate mail you forgot to authenticate.

Why You Need a Report Parser

Receivers send raw XML reports to your rua= address. Reading them manually is painful - they're verbose, count tens of thousands of records per day for active senders. Use a free parser:

Alignment - The Subtle Detail That Breaks DMARC

DMARC passes if EITHER SPF or DKIM passes WITH ALIGNMENT. Alignment means the From-domain matches the domain that authenticated.

Common breakage: you send via SendGrid with From: [email protected], but SendGrid uses MAIL FROM: [email protected]. SPF passes (sendgrid.net SPF is fine), but alignment fails (sendgrid.net ≠ yourdomain.com). DMARC fails unless DKIM aligns. Fix: configure custom DKIM at SendGrid using d=yourdomain.com.

Read the complete SPF + DKIM + DMARC guide

Covers alignment in depth, multi-provider DKIM, the 30-day rollout, and how to fix common failures.

Read the guide

More Free Tools