Monitoring (start here)
Delivery doesn't change. Receivers send daily aggregate reports so you can find every service that sends as your domain.
Fill in three fields. The record updates as you type, and every option is explained where you choose it.
Delivery doesn't change. Receivers send daily aggregate reports so you can find every service that sends as your domain.
A quarter of failing mail goes to spam; the rest is delivered as before. Raise pct as reports stay clean.
Full enforcement: mail that fails DMARC is refused. Subdomains get the same policy because sp is left out.
Quarantine for the main domain while blocking lookalike subdomains such as billing.example.com that never send mail.
Because reports go to another domain, that domain must publish a TXT record at example.com._report._dmarc.reports.vendor.example with the value v=DMARC1. Reporting services usually publish it for their customers.
Only an exact domain match aligns. Use it only when every sender signs and sends as example.com itself, not a subdomain.
Choose a policy (start with p=none), add a reporting address, and publish the generated value as a TXT record at _dmarc.yourdomain.com. Then check your DMARC record to confirm it's live.
Start with p=none to monitor without affecting delivery. Review your reports for 2-4 weeks, then move to p=quarantine and finally p=reject once legitimate senders all pass authentication.
The rua tag sets the address that receives aggregate XML reports. It's strongly recommended. Without it, you have no visibility into who is sending email as your domain. Use our DMARC analyzer to read the reports you receive.
In your DNS provider, create a TXT record with host _dmarc, paste the generated value, and keep the default TTL. A new record is usually visible within minutes; edits to an existing record can take up to its TTL.
No. Publishing multiple DMARC records at _dmarc causes receivers to ignore DMARC entirely. Replace your existing record instead of adding a second one.