Add a DMARC record in TransIP
If your domain's nameservers are ns0.transip.net, ns1.transip.nl and ns2.transip.eu, its DNS is at TransIP — those are TransIP's nameservers, used for domains registered through TransIP. You publish the record in the control panel's DNS settings.
The record you're publishing
| Field | Value |
|---|---|
| Name | _dmarc |
| TTL | Low — TransIP suggests 1 or 5 minutes |
| Type | TXT |
| Value | v=DMARC1; p=none; rua=mailto:… |
The Value is your DMARC policy. If you're setting up monitoring with DMARCmetric, Add your first domain generates the full value for you, including your workspace's unique rua= reporting address — copy it from the wizard with the copy button rather than retyping it. p=none is the right starting policy: it monitors everything and blocks nothing.
One thing to know first. While TransIP settings is switched on, TransIP manages your domain's records itself — and says the DMARC record is added automatically. To add or edit your own records you switch it off, and switching it back on later overwrites every record you configured, _dmarc included.
Don't add quote marks around the value: TransIP's DKIM guide says not to copy the quotation marks at the start and end of a value, because its DNS software adds them in the background.
The steps below add a new record, for a domain with no DMARC record yet. If _dmarc already has one, don't add another — edit the one you have instead.
Step by step
- In the control panel, go to Domain and select your domain in the left column (don't tick its box).
- Scroll to DNS settings, then DNS.
- If you don't see your records yet, click the switch behind TransIP settings to switch them off. Your domain's DNS records become visible and editable.
- Look for a TXT record whose Name is
_dmarc. If there is one, edit it instead. - Add a record with Name
_dmarc— without your domain; TransIP adds it in the background — and TypeTXT. - In Value, paste your
v=DMARC1; …value, without quote marks. - Click Save in the bottom right of the DNS section.
TransIP says DNS changes may take up to 24 hours before they're effective.
If you already have a DMARC record
A domain can have only one DMARC record, so don't add a new record — change the one that's there. Never add a second _dmarc record next to the old one: with two, email providers ignore both.
- In the DNS section, find the existing TXT record whose Name is
_dmarc. - Edit that record.
- What you change depends on what DMARCmetric shows you — check which of these two it is before you touch anything:
- If DMARCmetric shows only an address (
mailto:rua+…, shown when it couldn't read your DNS at that moment), don't replace anything. Add that address to your existingrua=tag, separated by a comma. If the record has norua=tag, add one:rua=followed by the address, separated from the tag before it by a semicolon. Leave your policy and every other tag as they are. - If DMARCmetric shows a full record (starting with
v=DMARC1), replace the record's whole Value with it. That value is built from your existing record: your policy and tags are kept, and it includes your DMARCmetric reporting address.
- If DMARCmetric shows only an address (
- Save the record.
If there are several. If the list shows more than one TXT record at _dmarc that starts with v=DMARC1, delete the extras and keep one, then change the one you keep exactly as in step 3: if DMARCmetric shows a full record, that record becomes its Value; if it shows only an address, add the address to its rua= tag. Until only one is left, receivers treat the domain as having no DMARC policy at all.
Verify it's live
From a terminal:
dig TXT _dmarc.example.com +short
You should see your v=DMARC1; … value echoed back in quotes. No terminal handy? Run your domain through the free DMARC checker — it fetches the live record and validates the syntax, which dig won't do. And if you added the record as part of DMARCmetric onboarding, press Verify DNS in the wizard; Verify your domain explains each result it can give you.
Common mistakes
- Switching TransIP settings back on. TransIP then overwrites all the DNS records you configured with its own — your
_dmarcrecord included. - Adding quote marks. TransIP's DKIM guide says not to copy them: its DNS software adds them in the background.
- Copying TransIP's example reporting address. Its TXT guide shows
rua=example@…withoutmailto:, which a DMARC reporting address needs. Paste DMARCmetric's full value instead. - Two
_dmarcrecords. A domain may have only one DMARC record; receivers treat two TXT records at_dmarcas no valid policy at all. If a record already exists, edit it — don't add a second. - Editing the value by hand. A missing semicolon between tags,
mailto;instead ofmailto:, or a mangled reporting address all invalidate the record or send your reports nowhere. Copy-paste the whole value, then confirm with the checker.
If some of your domains live at other providers, the same record works everywhere — the Cloudflare and GoDaddy walkthroughs cover those panels.