Generate a DMARC record
Pick a few options and get the exact TXT record to publish, with where it goes. Nothing is sent anywhere until you ask for it.
TXT
_dmarc
Auto or 3600
v=DMARC1; p=none
- Without a report address you won't see who sends as your domain, which makes tightening the policy guesswork.
Add it in your DNS provider as a new TXT record. Some providers want only _dmarc as the name and add your domain themselves. Replace any existing DMARC record rather than adding a second one.
Rather not manage this by hand?
We publish the DMARC record for you, read the daily reports, and move your policy from none to reject one click at a time when the reports say it is safe.
Choosing your first DMARC record
A DMARC record is one TXT record at _dmarc on your domain. The generator above writes it from your choices; the defaults are the safe start most domains should use.
Relaxed or strict alignment
Alignment decides whether a subdomain counts as your domain. Relaxed lets mail signed by mail.yourcompany.com pass for yourcompany.com, which is what almost every sending service needs. Strict is for domains that know every sender signs with the exact domain.
DMARC generator questions
Which policy should I start with?
p=none with a report address. It changes nothing about delivery and starts the daily reports, which show every service sending as your domain. Fix any that fail, then move to quarantine and reject.
What address should reports go to?
A mailbox you can read or a service that parses the reports. Reports are XML files, often several a day for a busy domain, so a dedicated address keeps them out of a personal inbox.
I already have a DMARC record. Should I add this one too?
No. Replace it. A domain with two DMARC records has none as far as receivers are concerned.
Is anything I type here stored?
No. The record is built in your browser. Only if you ask us to email it do we store your address and the domain.