Add a DMARC record in Route 53 or Lightsail
If your domain's nameservers look like ns-1234.awsdns-12.org, its DNS is hosted by AWS. That usually means an Amazon Route 53 hosted zone, but Amazon Lightsail DNS zones use the same kind of nameservers and have their own console, so this guide covers both. The record is identical everywhere; the Route 53 detail that trips people up is that TXT values go inside double quotes.
The record has to go in the zone your domain actually uses. Route 53 lets you create more than one hosted zone with the same name, and only the one your domain's registration points at is answered — see Common mistakes if a change never shows up.
The record you're publishing
| Field | Value |
|---|---|
| Record name | _dmarc |
| Record type | TXT |
| Value | "v=DMARC1; p=none; rua=mailto:…" (inside double quotes) |
| TTL (seconds) | 300 |
| Routing policy | Simple routing |
The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.
Route 53 stores a TXT value as one or more strings enclosed in double quotation marks, so the quotes you type are the record's delimiters, not part of your policy. One string holds up to 255 characters, which a DMARC record almost never needs; a longer value has to be split into several quoted strings on the same line.
The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.
Using Lightsail? Skip to its steps.
Step by step
- Open the Route 53 console at
console.aws.amazon.com/route53/and choose Hosted zones in the navigation pane. - Choose the name of your domain's hosted zone.
- Choose Create record. If the Choose routing policy page appears, choose Switch to quick create.
- In Record name, type
_dmarc— only the part in front of your domain, the way AWS's own guides enter names like_amazonses. Every record in a zone ends with the zone's name, so this is_dmarc.example.com. - For Record type, choose TXT – Text.
- In Value, paste your
v=DMARC1; …value inside double quotes:"v=DMARC1; p=none; rua=mailto:…". - Leave TTL (seconds) at 300 and Routing policy on Simple routing, then choose Create records.
AWS says changes generally reach all Route 53 name servers within 60 seconds. A resolver that asked for _dmarc before it existed may keep that "no such record" answer a little longer — with Route 53's default settings, up to 15 minutes.
If you already have a DMARC record
A domain can have only one DMARC record, so don't choose Create record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.
- In the hosted zone's list of records, find the existing TXT record whose Record name is
_dmarc. - Edit that record.
- What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
- If DMARCmetric shows only an address (
mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existingrua=tag, separated by a comma. If the record has norua=tag, add one:rua=followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are. - If DMARCmetric shows a full record (starting with
v=DMARC1), replace the record's whole Value with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address. Keep the value inside double quotes, as Route 53 requires:"v=DMARC1; …"— in Lightsail, leave the quotes out.
- If DMARCmetric shows only an address (
- Save the record.
If there are several. In Route 53, several values at one name live in one record, one per line of its Value box. If that box has more than one line holding a v=DMARC1 value, delete the extra lines and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that line becomes it, inside quotes; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.
Using Amazon Lightsail DNS instead
If the Route 53 console shows no hosted zone for your domain — or the hosted zone's name servers aren't the ones your domain uses — its DNS may be in Lightsail. For a domain registered in Route 53, Lightsail can take over its DNS: it points the domain at a Lightsail zone and deletes the Route 53 hosted zone.
- In the Lightsail console (
lightsail.aws.amazon.com), open Domains & DNS and choose your domain's DNS zone. - On its DNS records tab, add a TXT record.
- In Record name, enter
_dmarc. In Responds with, paste yourv=DMARC1; …value. Lightsail's documentation says the text doesn't need to be enclosed in quotes, so leave them out here. - Save the record. Lightsail doesn't let you set a TTL — its records always use 60 seconds.
The one-record rule is the same: if a TXT record at _dmarc is already listed, change that one instead of adding a second — exactly as in the section above, minus the quotes.
Verify it's live
From a terminal:
dig TXT _dmarc.example.com +short
You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.
Common mistakes
- Leaving out the quotes in Route 53. AWS documents every TXT value as strings enclosed in double quotation marks. Paste
"v=DMARC1; …"with a quote at the very start and the very end. (Only a value longer than 255 characters is split into several quoted pieces — a DMARC record almost never is.) - Quotes in Lightsail. Lightsail's documentation says the text doesn't need to be enclosed in quotes — paste the value without them.
- Editing the wrong hosted zone. Two hosted zones can share a name, each with its own name servers, and Route 53 only answers from the one your domain's registration uses. If your record never shows up, open the zone you edited (select it, then View details), compare its Name servers with the domain's, and make the change in the zone that matches.
- A private hosted zone. Records in a private hosted zone only answer inside your VPCs.
_dmarchas to be in the public hosted zone to reach receivers. - Two
_dmarcvalues. A domain may have only one DMARC record. In Route 53 a second one shows up as a second line in the same record's Value box — delete it rather than keeping both. - Editing the value by hand. A missing semicolon between tags,
mailto;instead ofmailto:, or a mangled reporting address all invalidate the record or send your reports nowhere. Copy-paste the whole value, then confirm with the checker.
If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.