Free email-authentication toolkit

Free DMARC record
generator.

Build a valid _dmarc TXT record in seconds. Choose your policy, add reporting addresses and tune alignment settings — the record updates live as you type. No signup, no backend: everything runs right here in your browser.

Live preview 100% client-side Always free

DMARC record generator

Build a valid _dmarc TXT record. Adjust the options and the record updates live — start at p=none to monitor safely, then ramp toward enforcement.

Policy p

Monitoring only — nothing is blocked. The safe starting point.

Subdomain policy sp

Policy applied to subdomains. "Inherit" omits the tag and reuses p.

Where daily XML summaries are sent. Strongly recommended — without it you stay blind.

Per-message failure samples. Few receivers send these; leave blank if unsure.

100%

Share of mail the policy applies to. Ramp up gradually (e.g. 25 → 50 → 100) when enforcing.

DKIM alignment adkim
SPF alignment aspf

The basics, briefly

DMARC explained

What is a DMARC record?

DMARC (Domain-based Message Authentication, Reporting & Conformance) is a DNS TXT record published at _dmarc.yourdomain.com. It tells receiving mail servers what to do with messages that fail SPF and DKIM alignment, and where to send aggregate reports so you can monitor your sending sources. Use the generator above to build yours in seconds — then verify it with our DMARC checker.

How do I publish my DMARC record?

Copy the generated record above, then log in to your DNS provider (Cloudflare, Route 53, GoDaddy, etc.). Create a TXT record with the hostname _dmarc (some providers ask for the full _dmarc.yourdomain.com) and paste the record as the value. Changes typically propagate within minutes. Confirm it with the DMARC checker or read DMARC record tags explained for a full tag reference.

Should I start with p=none or p=reject?

Always start with p=none and a valid rua address. This lets you collect aggregate reports for 2–4 weeks without affecting mail delivery. Once you've identified and aligned every legitimate sending source, move to p=quarantine at a low pct (say 25%), then gradually raise it. Only advance to p=reject at 100% when your reports are clean. Rushing to reject can cause legitimate mail to bounce.

More free tools