Skip to main content
Free tool

Generate a DMARC record

Pick a few options and get the exact TXT record to publish, with where it goes. Nothing is sent anywhere until you ask for it.

Policy
Type
TXT
Host / name
_dmarc
TTL
Auto or 3600
Value
v=DMARC1; p=none
  • Without a report address you won't see who sends as your domain, which makes tightening the policy guesswork.

Add it in your DNS provider as a new TXT record. Some providers want only _dmarc as the name and add your domain themselves. Replace any existing DMARC record rather than adding a second one.

Rather not manage this by hand?

We publish the DMARC record for you, read the daily reports, and move your policy from none to reject one click at a time when the reports say it is safe.

About DMARC

Choosing your first DMARC record

A DMARC record is one TXT record at _dmarc on your domain. The generator above writes it from your choices; the defaults are the safe start most domains should use.

Relaxed or strict alignment

Alignment decides whether a subdomain counts as your domain. Relaxed lets mail signed by mail.yourcompany.com pass for yourcompany.com, which is what almost every sending service needs. Strict is for domains that know every sender signs with the exact domain.

DMARC generator questions

Which policy should I start with?

p=none with a report address. It changes nothing about delivery and starts the daily reports, which show every service sending as your domain. Fix any that fail, then move to quarantine and reject.

What address should reports go to?

A mailbox you can read or a service that parses the reports. Reports are XML files, often several a day for a busy domain, so a dedicated address keeps them out of a personal inbox.

I already have a DMARC record. Should I add this one too?

No. Replace it. A domain with two DMARC records has none as far as receivers are concerned.

Is anything I type here stored?

No. The record is built in your browser. Only if you ask us to email it do we store your address and the domain.