Validate and analyze DMARC TXT records directly in your browser. Quickly check policy correctness, detect configuration issues, and understand each tag without digging through documentation.
Policy, alignment and reporting addresses, with common mistakes flagged.
Runs in your browserValidation summary
How to use
- Paste your DMARC TXT record into the input field
- Click Validate record
- Review validation status and detected issues
- Check tag explanations and normalized output
- Copy the corrected record if needed
FAQ
What is a DMARC record and why does it matter?
A DMARC record is a DNS TXT record that tells receiving mail servers how to handle messages that fail SPF or DKIM checks. It helps prevent spoofing and phishing by enforcing policies and enabling reporting.
Without DMARC, attackers can impersonate your domain more easily.
What does a valid DMARC record look like?
A minimal valid DMARC record must include:
v=DMARC1(version)p=policy (none,quarantine, orreject)
Example:
v=DMARC1; p=none;
This record enables monitoring without enforcing restrictions.
What does 'pct' mean and why do I see a warning?
The pct tag defines what percentage of failing emails the policy applies to.
Example:
v=DMARC1; p=quarantine; pct=5;
This means only 5% of failing messages will be affected.
The tool shows a warning because production setups usually use pct=100 unless you're gradually rolling out enforcement.
What is the difference between p=none, quarantine, and reject?
none→ monitoring only (no action)quarantine→ send suspicious emails to spamreject→ block failing emails completely
Example:
v=DMARC1; p=reject;
This is the strictest and most secure configuration.
What are rua and ruf and how should they be formatted?
rua and ruf define where reports are sent:
rua→ aggregate reportsruf→ forensic (failure) reports
Example:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com;
Each value must start with mailto:. Multiple addresses are comma-separated.
Why is my DMARC record marked as 'valid with warnings'?
This means the syntax is correct, but something may not follow best practices.
Common cases:
pctis less than 100- missing reporting (
rua) - record order is unusual
- unknown or duplicate tags
The tool now shows exactly what to fix and how to improve it.
What is a recommended production DMARC record?
A common secure configuration looks like this:
v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com; pct=100;
This enforces strict protection and enables reporting.
Practical example
Input:
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; pct=100;
What you’ll see:
- Validation status (valid or warnings)
- Parsed tags with explanations
- Normalized DMARC record ready to copy
Related guides and tools
Related guides
- nslookup in Windows: DNS troubleshooting from basic queries to AD diagnostics - resolving the same records from the Windows command line
- SPF, DKIM and DMARC: why a TXT query finds only SPF - how DMARC uses SPF and DKIM, why alignment decides the result, and which records a subdomain inherits
- DNS record types cheat sheet: every DNS record type and what it is for, on one printable page.