Add a DMARC record in IONOS
If your domain's nameservers look like ns1045.ui-dns.com, ns1045.ui-dns.de, ns1045.ui-dns.org and ns1045.ui-dns.biz — the number varies — its DNS is at IONOS: that's the pattern IONOS documents for its default nameservers. You publish the record in the domain's DNS settings.
The record you're publishing
| Field | Value |
|---|---|
| Type | TXT |
| Host name | _dmarc |
| Value | v=DMARC1; p=none; rua=mailto:… |
| TTL | Optional |
The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.
IONOS's DNS help says a domain has no TXT records by default — but look for an existing _dmarc record anyway before adding one.
The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.
Step by step
- Log in to IONOS and go to Domains & SSL.
- For your domain, click the gear symbol under Actions and select DNS.
- Your existing records are listed there. If one is a TXT record with the host name
_dmarc, edit it instead. - Click Add Record and, under Type, select TXT.
- In Host name, enter
_dmarc. IONOS creates_dmarc.your-domain.comfrom it automatically. - In Value, paste your
v=DMARC1; …value. - Optionally select a TTL, then click Save.
IONOS says changes take effect at IONOS immediately, and it may take up to an hour until they're effective everywhere.
If you already have a DMARC record
A domain can have only one DMARC record, so don't click Add Record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.
- In the DNS section, find the existing TXT record whose host name is
_dmarc, click the gear symbol under Actions and select Edit record. - Edit that record.
- What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
- If DMARCmetric shows only an address (
mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existingrua=tag, separated by a comma. If the record has norua=tag, add one:rua=followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are. - If DMARCmetric shows a full record (starting with
v=DMARC1), replace the record's whole Value with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address.
- If DMARCmetric shows only an address (
- Save the record.
If there are several. If the list shows more than one TXT record at _dmarc that starts with v=DMARC1, delete the extras and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that record becomes its Value; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.
Verify it's live
From a terminal:
dig TXT _dmarc.example.com +short
You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.
Common mistakes
- Adding your domain to the host name. IONOS adds
.your-domain.comitself — enter only_dmarc. - Two
_dmarcrecords. A domain may have only one DMARC record; receivers treat two TXT records at_dmarcas no valid policy at all. If a record already exists, edit it — don't add a second. - Editing the value by hand. A missing semicolon between tags,
mailto;instead ofmailto:, or a mangled reporting address all invalidate the record or send your reports nowhere. Copy-paste the whole value, then confirm with the checker.
If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.