Add a DMARC record in Hover
If your domain's nameservers are ns1.hover.com and ns2.hover.com, its DNS is at Hover — those are Hover's default nameservers, and Hover manages a domain's DNS records only while it uses them.
The record you're publishing
| Field | Value |
|---|---|
| Type | TXT |
| Hostname | _dmarc |
| Content | v=DMARC1; p=none; rua=mailto:… |
The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.
The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.
Step by step
- Sign in to Hover, click Domains and select your domain.
- Click DNS. If a TXT record with the hostname
_dmarcis already listed, edit it instead. - Click Add a record, and choose TXT as the Type.
- In Hostname, enter
_dmarc, the way Hover's own DMARC guide does. - In Content, paste your
v=DMARC1; …value. - Click Save.
Hover says DNS changes can take up to 24–48 hours to fully propagate.
If you already have a DMARC record
A domain can have only one DMARC record, so don't click Add a record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.
- In the domain's DNS records, find the existing TXT record whose hostname is
_dmarc. - Edit that record.
- What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
- If DMARCmetric shows only an address (
mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existingrua=tag, separated by a comma. If the record has norua=tag, add one:rua=followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are. - If DMARCmetric shows a full record (starting with
v=DMARC1), replace the record's whole Content with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address.
- If DMARCmetric shows only an address (
- Save the record.
If there are several. If the list shows more than one TXT record at _dmarc that starts with v=DMARC1, delete the extras and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that record becomes its Content; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.
Verify it's live
From a terminal:
dig TXT _dmarc.example.com +short
You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.
Common mistakes
- Two
_dmarcrecords. A domain may have only one DMARC record; receivers treat two TXT records at_dmarcas no valid policy at all. If a record already exists, edit it — don't add a second. - Deleting the wrong record. Hover warns that deleting a DNS record can immediately disconnect the service tied to it. When you remove an extra
_dmarcrecord, check you're deleting the TXT record at_dmarcand nothing else. - Editing the value by hand. A missing semicolon between tags,
mailto;instead ofmailto:, or a mangled reporting address all invalidate the record or send your reports nowhere. Copy-paste the whole value, then confirm with the checker.
If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.