Free · No signup · DMARC, SPF and DKIM
DMARC Record Generator
Build a valid DMARC record in under a minute, publish it at _dmarc, and confirm it's live. It's the record Gmail, Yahoo and Outlook require from bulk senders.
- Starts you at
p=none, so no legitimate mail gets blocked - Validates your report address and flags third-party authorization
- Publishing steps for Cloudflare, GoDaddy, Route 53 and others
Generate your record
3 fields · advanced optional- Type
- TXT
- Host
- _dmarc · _dmarc.yourdomain.com
- Value
- v=DMARC1; p=none
Publish it in your DNS
- Sign in where you manage DNS for
yourdomain.com(your registrar or a DNS host such as Cloudflare) and add a TXT record. - Set the host or name to
_dmarc. Most providers add the domain for you; if yours asks for the full name, use_dmarc.yourdomain.com. - Paste the value you copied, keep the default TTL and save.
- New records usually show up within minutes. Check that it's live.
Want exact steps for Cloudflare, GoDaddy, Route 53 or Namecheap, or options like a subdomain policy?
Open your record in the full builderCheck DMARC, SPF and DKIM in one pass
See your policy, SPF lookup count and DKIM selectors on one page, with fixes ranked by impact.
Checking many domains? Bulk lookup takes up to 50 at once.Every tool between you and p=reject
Seven free tools. No account, no email capture.
Create
Create DMARC recordPolicy, reporting and alignment in one form, with a live preview.SPF record generatorPick your email providers and stay under the 10-lookup limit.From p=none to p=reject without losing mail
Most domains take a few weeks to a few months. Each step has a tool.
- 01 · p=none
Publish a monitoring record
Add a record with a report address. Delivery doesn't change.
Generate record - 02 · rua reports
Read your reports
Google, Microsoft, Yahoo and others send daily XML. Find every service sending as you.
Analyze reports - 03 · SPF + DKIM
Authorize every sender
Add each legitimate service to SPF and align its DKIM signature with your domain.
Check SPF and DKIM - 04 · p=reject
Enforce
Move to quarantine, then reject, once reports show only legitimate mail passing.
Update policy
What a DMARC record looks like
- v
- Version. Always
DMARC1, and always the first tag. - p
- Policy for mail that fails:
none,quarantineorreject. - sp
- Policy for subdomains. Uses
pwhen left out. - rua
- Where receivers send daily aggregate reports.
- adkim · aspf
- Alignment.
r(relaxed, the default) lets subdomains align;sneeds an exact match. - pct
- Share of failing mail the policy applies to. Defaults to 100.
How do I generate a DMARC record?
Use the DMARC record generator at the top of this page. Pick a policy (start with p=none, which doesn't change delivery), add an address for reports, and copy the TXT record it builds. Publish it at _dmarc.yourdomain.com with your DNS provider, then confirm it with the DMARC checker.
What is a DMARC record and why do I need one?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS TXT record that tells receivers what to do with mail that uses your domain in the From address but fails SPF and DKIM checks, and where to send reports about it. Without one, receivers have no instructions from you, and Gmail, Yahoo and Outlook.com require one from bulk senders.
What does a DMARC record look like?
A DMARC record is a DNS TXT record published at _dmarc.yourdomain.com. A typical starting record looks like: v=DMARC1; p=none; rua=mailto:reports@yourdomain.com. The v tag declares the DMARC version, the p tag sets the policy for emails that fail authentication, and the rua tag tells receivers where to send aggregate reports.
Where do I add my DMARC record?
Log in to your DNS provider (Cloudflare, GoDaddy, Route 53, Namecheap, etc.), create a new TXT record, set the host or name field to _dmarc, and paste the generated record as the value. A new record is usually visible within minutes, and you can confirm it is live with our DMARC checker.
Is this DMARC generator free?
Yes. The DMARC record generator, the DMARC, SPF, and DKIM checkers, the report analyzer, and the bulk lookup tool are all completely free, with no signup, no email capture, and no limits for normal use.
What is SPF and how does it protect my domain?
SPF (Sender Policy Framework) is a DNS record that lists which mail servers are authorized to send email on behalf of your domain. When a receiving server gets an email, it checks whether the sending server's IP address is on that list. Without SPF, receivers can't tell your servers from anyone else's.
What is DKIM and how does it work?
DKIM (DomainKeys Identified Mail) adds a digital signature to your outgoing emails using a private key. The corresponding public key is published in your DNS. Receiving servers use the public key to check the signature, which shows the message wasn't changed in transit and was signed with your domain's key.
How do DMARC, SPF, and DKIM work together?
SPF verifies which servers can send as your domain. DKIM proves messages haven't been tampered with. DMARC ties them together by checking that at least one passes with proper domain alignment, and it tells receiving servers what to do when checks fail: monitor, quarantine, or reject. Set up all three: SPF breaks when mail is forwarded, DKIM covers that case, and DMARC is what tells receivers to act on failures.
What's the difference between DMARC policies (none, quarantine, reject)?
The policy tells receivers what to do with mail that fails DMARC. 'none' asks them to deliver it as normal and send you reports, 'quarantine' asks them to put it in the spam folder, and 'reject' asks them to refuse it. Start at 'none', then move to 'quarantine' and 'reject' once your reports show your own mail passing.
What is the SPF 10 DNS lookup limit?
The SPF specification limits each record to 10 DNS lookups, counting 'include', 'a', 'mx', 'ptr', 'exists' and 'redirect', including the lookups inside nested includes. Exceeding this limit causes SPF validation to fail with a 'permerror', which means receiving servers treat your email as unauthenticated. Our SPF checker counts your lookups and flags when you're over the limit.
How do I find my DKIM selector?
DKIM selectors are found in the DKIM-Signature header of your sent emails. Look for the 's=' tag. Common selectors include 'google' for Google Workspace, 'selector1' and 'selector2' for Microsoft 365, and 'k1' for Mailchimp. Our DKIM checker scans the selectors used by popular providers automatically.
How long do DNS record changes take to propagate?
A new DMARC, SPF or DKIM record is usually visible within minutes of saving it at your DNS provider. If you edit an existing record, resolvers can keep serving the old value until its TTL (Time To Live) expires, often an hour. The 24-48 hour figure you may have seen applies to nameserver changes, not new records. Use our checkers to confirm your records are live.
Can I use these tools for multiple domains?
Yes. Each domain needs its own DMARC, SPF and DKIM records, and every tool here works for any domain. To check DMARC and SPF for up to 50 domains at once, use the bulk lookup.