Skip to content
Email & DNS

DMARC Record Generator

Create a DMARC policy record step by step – from monitoring (p=none) to full protection (p=reject) – with reporting addresses and alignment.

Runs in your browser – nothing is sent or stored.

DMARC ties SPF and DKIM together and tells receiving servers what to do with mail that fails – and it sends you reports showing who is sending as your domain. Build the record step by step and follow the safe roll-out path from monitoring to full protection.

The safe roll-out

  1. p=none with a rua address – collect reports for 2–4 weeks.
  2. Fix every legitimate sender that fails (add it to SPF or set up DKIM).
  3. p=quarantine – failures go to spam. Optionally start with pct=25.
  4. p=reject – spoofed mail is refused. Keep reading the reports.

Frequently asked questions

Where does the record go?

Create a TXT record named _dmarc (for example _dmarc.example.com) with the generated value.