Add a DMARC record in Openprovider
If your domain's nameservers are ns1.openprovider.nl, ns2.openprovider.be and ns3.openprovider.eu, its DNS zone is hosted by Openprovider. Openprovider is a registrar that works through resellers — hosting companies, agencies and web designers — and doesn't deal with domain owners directly. So the first question isn't where to click; it's who holds the login.
Who can change the record
- You have your own Openprovider account (you are the reseller): follow the steps below.
- You bought the domain or hosting from someone else: they can publish the record for you — send them the record in the table below. Openprovider also lets resellers give a customer a DNS panel for a single domain, at
dnspanel.io, without Openprovider's name on it — if that's what you were given, add the record there.
The record you're publishing
| Field | Value |
|---|---|
| Name | _dmarc |
| Type | TXT |
| Value | "v=DMARC1; p=none; rua=mailto:…" (inside double quotes) |
The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.
The quotes are required. Openprovider asks for every TXT value to be surrounded by double quotes and warns that, without them, the entire zone can fail to resolve correctly — not just this record.
The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.
Step by step
- In the Openprovider control panel, open DNS Management and go to the overview of your DNS zones.
- Open your domain's zone.
- Add a record.
- In Name, type
_dmarc— only the part in front of your domain. Openprovider's own DMARC guide does the same: the record then answers at_dmarc.yourdomain.com. - Set Type to
TXT. - In Value, paste your
v=DMARC1; …value inside double quotes:"v=DMARC1; p=none; rua=mailto:…". - Save the record.
In a dnspanel.io panel, a record is added with + New Record, then create.
Openprovider says a newly added record should be available rather quickly. A record you edit can take longer: resolvers keep the old value until its TTL runs out.
If you already have a DMARC record
A domain can have only one DMARC record, so don't add a new record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.
- In the zone's list of records, find the existing TXT record whose Name is
_dmarc. - Edit that record.
- What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
- If DMARCmetric shows only an address (
mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existingrua=tag, separated by a comma. If the record has norua=tag, add one:rua=followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are. - If DMARCmetric shows a full record (starting with
v=DMARC1), replace the record's whole Value with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address. Keep the value inside double quotes — Openprovider requires them:"v=DMARC1; …".
- If DMARCmetric shows only an address (
- Save the record.
If there are several. If the list shows more than one TXT record at _dmarc that starts with v=DMARC1, delete the extras and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that record becomes its Value; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.
Verify it's live
From a terminal:
dig TXT _dmarc.example.com +short
You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.
Common mistakes
- Leaving out the quotes. Openprovider requires them around TXT values, and without them the whole zone can stop resolving correctly.
- A
_dmarcCNAME already in the zone. A CNAME can't sit next to any other record at the same name, a TXT record included. Some DMARC services are set up with a CNAME at_dmarc— Openprovider adds one automatically for EasyDMARC — so if the list shows a CNAME there, that service is still wired in. Decide which one you're using before you change anything. - Two
_dmarcrecords. A domain may have only one DMARC record; receivers treat two TXT records at_dmarcas no valid policy at all. If a record already exists, edit it — don't add a second. - Editing a zone that isn't live. A zone that isn't active on Openprovider's nameservers (a "shadow zone") doesn't answer anyone — for example after the domain has left the reseller's account. Check the domain's nameservers first.
- Editing the value by hand. A missing semicolon between tags,
mailto;instead ofmailto:, or a mangled reporting address all invalidate the record or send your reports nowhere. Copy-paste the whole value, then confirm with the checker.
If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.