DMARCmetric

Add a DMARC record in Route 53 or Lightsail

Updated 2026-09-30 · Setup Guides

If your domain's nameservers look like ns-1234.awsdns-12.org, its DNS is hosted by AWS. That usually means an Amazon Route 53 hosted zone, but Amazon Lightsail DNS zones use the same kind of nameservers and have their own console, so this guide covers both. The record is identical everywhere; the Route 53 detail that trips people up is that TXT values go inside double quotes.

The record has to go in the zone your domain actually uses. Route 53 lets you create more than one hosted zone with the same name, and only the one your domain's registration points at is answered — see Common mistakes if a change never shows up.

The record you're publishing

FieldValue
Record name_dmarc
Record typeTXT
Value"v=DMARC1; p=none; rua=mailto:…" (inside double quotes)
TTL (seconds)300
Routing policySimple routing

The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.

Route 53 stores a TXT value as one or more strings enclosed in double quotation marks, so the quotes you type are the record's delimiters, not part of your policy. One string holds up to 255 characters, which a DMARC record almost never needs; a longer value has to be split into several quoted strings on the same line.

The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.

Using Lightsail? Skip to its steps.

Step by step

  1. Open the Route 53 console at console.aws.amazon.com/route53/ and choose Hosted zones in the navigation pane.
  2. Choose the name of your domain's hosted zone.
  3. Choose Create record. If the Choose routing policy page appears, choose Switch to quick create.
  4. In Record name, type _dmarc — only the part in front of your domain, the way AWS's own guides enter names like _amazonses. Every record in a zone ends with the zone's name, so this is _dmarc.example.com.
  5. For Record type, choose TXT – Text.
  6. In Value, paste your v=DMARC1; … value inside double quotes: "v=DMARC1; p=none; rua=mailto:…".
  7. Leave TTL (seconds) at 300 and Routing policy on Simple routing, then choose Create records.

AWS says changes generally reach all Route 53 name servers within 60 seconds. A resolver that asked for _dmarc before it existed may keep that "no such record" answer a little longer — with Route 53's default settings, up to 15 minutes.

If you already have a DMARC record

A domain can have only one DMARC record, so don't choose Create record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.

  1. In the hosted zone's list of records, find the existing TXT record whose Record name is _dmarc.
  2. Edit that record.
  3. What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
    • If DMARCmetric shows only an address (mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existing rua= tag, separated by a comma. If the record has no rua= tag, add one: rua= followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are.
    • If DMARCmetric shows a full record (starting with v=DMARC1), replace the record's whole Value with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address. Keep the value inside double quotes, as Route 53 requires: "v=DMARC1; …" — in Lightsail, leave the quotes out.
  4. Save the record.

If there are several. In Route 53, several values at one name live in one record, one per line of its Value box. If that box has more than one line holding a v=DMARC1 value, delete the extra lines and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that line becomes it, inside quotes; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.

Using Amazon Lightsail DNS instead

If the Route 53 console shows no hosted zone for your domain — or the hosted zone's name servers aren't the ones your domain uses — its DNS may be in Lightsail. For a domain registered in Route 53, Lightsail can take over its DNS: it points the domain at a Lightsail zone and deletes the Route 53 hosted zone.

  1. In the Lightsail console (lightsail.aws.amazon.com), open Domains & DNS and choose your domain's DNS zone.
  2. On its DNS records tab, add a TXT record.
  3. In Record name, enter _dmarc. In Responds with, paste your v=DMARC1; … value. Lightsail's documentation says the text doesn't need to be enclosed in quotes, so leave them out here.
  4. Save the record. Lightsail doesn't let you set a TTL — its records always use 60 seconds.

The one-record rule is the same: if a TXT record at _dmarc is already listed, change that one instead of adding a second — exactly as in the section above, minus the quotes.

Verify it's live

From a terminal:

dig TXT _dmarc.example.com +short

You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.

Common mistakes

If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.

Still stuck?

We answer every message — usually within one business day.

Email [email protected]