Add a DMARC record in Porkbun
If your domain's nameservers are curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com and salvador.ns.porkbun.com, Porkbun is your DNS host — those are the four default nameservers Porkbun lists. That's true even for a domain registered somewhere else: Porkbun's DNS can host an external domain. You publish the record in Porkbun's DNS records editor.
The record you're publishing
| Field | Value |
|---|---|
| Type | TXT - Text record |
| Host | _dmarc |
| Answer | v=DMARC1; p=none; rua=mailto:… |
| TTL | Default |
The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.
If you host email with Porkbun, check first: Porkbun's Configure DMARC button, shown to domains with its email hosting, publishes a DMARC record for you.
The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.
Step by step
- Click ACCOUNT in the top-right corner and select Domain Management.
- Find your domain and click the DNS button under its name. (Or open Details and click the edit icon under DNS RECORDS.)
- In Manage DNS Records, look for a TXT record whose Host is
_dmarc. If there is one, edit it instead. - Click Add Record, and set Type to TXT - Text record.
- In Host, enter
_dmarc— only the subdomain part, the way Porkbun's own guides enter it. - In Answer, paste your
v=DMARC1; …value. - Leave TTL on its default and click Add.
Porkbun says a new record usually resolves everywhere moments after you click Add; a changed record takes longer. If your own computer looked up _dmarc before the record existed, it may keep failing there for a few hours — what Porkbun calls negative caching.
If you already have a DMARC record
A domain can have only one DMARC record, so don't click Add Record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.
- In Manage DNS Records, find the existing TXT record whose Host is
_dmarc, and click the pencil icon to its right. - Edit that record.
- What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
- If DMARCmetric shows only an address (
mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existingrua=tag, separated by a comma. If the record has norua=tag, add one:rua=followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are. - If DMARCmetric shows a full record (starting with
v=DMARC1), replace the record's whole Answer with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address.
- If DMARCmetric shows only an address (
- Save the record.
If there are several. If the list shows more than one TXT record at _dmarc that starts with v=DMARC1, delete the extras and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that record becomes its Answer; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.
Verify it's live
From a terminal:
dig TXT _dmarc.example.com +short
You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.
Common mistakes
- A second record next to Porkbun's. If you used Configure DMARC for Porkbun email hosting, a DMARC record is already published. Edit it rather than adding another.
- Typing the whole domain in Host. Porkbun wants only the subdomain part —
_dmarc— not the full name; its API guide says not to include the domain name itself. - Two
_dmarcrecords. A domain may have only one DMARC record; receivers treat two TXT records at_dmarcas no valid policy at all. If a record already exists, edit it — don't add a second. - Editing the value by hand. A missing semicolon between tags,
mailto;instead ofmailto:, or a mangled reporting address all invalidate the record or send your reports nowhere. Copy-paste the whole value, then confirm with the checker.
If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.