DMARC (Domain-based Message Authentication, Reporting, and Conformance) is a powerful email authentication protocol that builds on SPF and DKIM to provide domain-level email authentication and policy enforcement. Our DMARC Checker tool validates your DMARC record configuration, checks policy settings, and provides recommendations for optimal email security. DMARC helps prevent email spoofing, phishing attacks, and protects your domain reputation. Proper DMARC configuration is essential for organizations that send email and want to protect their brand and users from email-based attacks.
How it works
Enter your domain name, and our tool queries your DNS for the DMARC record (stored as a TXT record at _dmarc.yourdomain.com).
The DMARC record is parsed and validated, checking for proper syntax, policy settings, and reporting configurations.
Each component is analyzed: policy (none, quarantine, reject), subdomain policy, reporting addresses, and percentage settings.
The tool checks for common configuration issues and provides guidance on policy strength and reporting setup.
Results include validation status, policy interpretation, and step-by-step recommendations for implementation.
Why it matters
Prevent email spoofing and phishing by enforcing policies that reject or quarantine unauthorized emails.
Protect your brand reputation by ensuring only authorized senders can use your domain in email communications.
Gain visibility into email authentication with DMARC reporting that shows who is sending emails on your behalf.
Improve email deliverability by demonstrating to email providers that you take email security seriously.
Comply with industry best practices and security standards that major organizations and email providers recommend.
FAQ
What are the DMARC policy options?
DMARC policies are: "none" (monitor only, take no action), "quarantine" (mark suspicious emails as spam), and "reject" (reject unauthorized emails entirely). Start with "none" for monitoring, then move to stricter policies.
How do I set up DMARC reporting?
Add "rua" (aggregate reports) and "ruf" (forensic reports) tags to your DMARC record with email addresses where you want to receive reports. This helps you monitor email authentication and identify issues.
Should I start with a strict DMARC policy?
No, it's recommended to start with "p=none" to monitor email authentication without affecting delivery. Once you verify all legitimate email sources are properly authenticated, gradually move to "quarantine" and then "reject".
Open the interactive tool on this page after JavaScript loads, or contact us if something is broken.