Free Tool · Runs in your browser

DMARC Record Checker

Look up the _dmarc record for any domain. We validate the syntax, explain every tag, grade your policy strength and tell you when it is safe to move from p=none to p=quarantine or p=reject.

  • 100% free
  • No signup
  • Nothing leaves your browser

DMARC Record Checker

We look up the TXT record at _dmarc.yourdomain.com live.

Results appear here

Enter a domain to see its DMARC policy, every tag explained, a policy grade and how to strengthen it.

How It Works

Three steps, no account needed

  1. 1

    Enter a domain

    Type the domain in your From address. We query _dmarc.yourdomain.com over DNS-over-HTTPS.

  2. 2

    We parse and grade the policy

    Every tag is validated and explained, reporting addresses are checked and the policy is graded from A to F.

  3. 3

    Follow the upgrade path

    The result tells you whether to add reporting, move from none to quarantine, or go to reject, with the record to paste.

Domain & DNS Checkers

What DMARC adds on top of SPF and DKIM

SPF and DKIM each prove something about a message, but neither checks the domain the recipient actually sees in the From header. DMARC closes that gap. It requires that the domain which passed SPF or DKIM aligns with the From domain, and it tells receivers what to do when that fails: deliver anyway (none), send to spam (quarantine) or refuse (reject).

It also asks receivers to send you aggregate reports describing every source sending as your domain and whether it passed. For a cold email operation, DMARC is how you stop lookalike spoofing and how you notice a misconfigured tool before it burns a domain.

_dmarc.yourdomain.com  TXT
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100

Moving from p=none to quarantine to reject

Start at p=none with a rua address. Nothing changes for delivery, but within a few days you will receive XML reports listing every IP that sent mail using your domain. Check that your mailbox provider, sending tool and any CRM all pass with alignment. Once only expected sources appear and they all pass, change to p=quarantine.

Run at quarantine for a few weeks. If nothing legitimate is being quarantined, switch to p=reject. Gmail and Yahoo require at least p=none from bulk senders, but receivers give more credit to enforced policies, and reject is the only setting that fully stops spoofing.

  • Use pct=25 or pct=50 to roll out quarantine gradually if you are nervous.
  • Set sp= if subdomains need a different policy; otherwise they inherit p.
  • Keep adkim and aspf relaxed unless every sender uses the exact From domain.
  • Re-read reports whenever you add a new sending tool.

Reading the tags that matter

The record is a list of tag=value pairs separated by semicolons. v must be DMARC1 and must come first. p is the only other required tag. rua takes one or more mailto: addresses for aggregate reports. pct limits how much failing mail the policy applies to. adkim and aspf switch alignment between relaxed (subdomains count) and strict (exact match). Everything else is optional and rarely needed.

A common mistake is sending reports to a third-party address without the authorisation record that domain must publish. Another is adding two DMARC records, which makes the policy undefined. The checker flags both, along with typos that turn a real tag into an unknown one that receivers ignore.

DMARC for cold email domains

Outreach domains are frequent spoofing targets because they are new and rarely monitored. A reject policy costs nothing once your own mail aligns, and it removes a whole class of reputation damage. Because most cold email setups send through Google Workspace or Microsoft 365 with DKIM enabled, alignment is normally already in place.

InboxOne publishes SPF, DKIM and a DMARC record on every domain it provisions, so a domain is protected from the first send. If you manage DNS yourself, use the generator to build the record and this checker to confirm it after propagation.

FAQ

Frequently asked questions

Still stuck? Book a 30-minute deliverability call and we'll look at your setup together.

Enter your domain above. The checker queries the TXT record at _dmarc.yourdomain.com, confirms it starts with v=DMARC1, validates every tag and grades the policy. If nothing is published you get a starting record to paste into DNS.

p=none monitors only: failing mail is delivered and merely reported. p=quarantine sends failing mail to spam. p=reject refuses it outright. Start at none to collect reports, then move to quarantine and finally reject once your legitimate mail passes alignment consistently.

It is optional but strongly recommended. Without rua you receive no aggregate reports, so you cannot see which sources are sending as your domain or whether your own tools are failing alignment. Use rua=mailto:dmarc@yourdomain.com or a DMARC reporting service address.

It meets the minimum: both require bulk senders to publish a DMARC record with at least p=none. It does not, however, stop anyone spoofing your domain. For cold email domains, plan to reach quarantine or reject once reports confirm alignment.

Alignment means the domain that passed SPF or DKIM matches the domain in the From header. Relaxed alignment (the default) accepts subdomains; strict requires an exact match. At least one of SPF or DKIM must pass and align for DMARC to pass.

The usual causes are v=DMARC1 not being the first tag, a missing or misspelled p tag, two DMARC records on the same name, or a rua address that is not a proper mailto: URI. The checks section names the exact problem and the fix.

Ready to Scale Your Outbound?

Your Cold Email Infrastructure Shouldn't Be the Bottleneck.

Domains, mailboxes, DNS, deliverability, and platform exports — all from one dashboard. Starting at $39/month for 10 production-ready mailboxes.

Inbox One Logo

Cold email infrastructure platform. Buy domains, provision Google Workspace mailboxes, auto-configure DNS, and export to 5 outreach platforms — all from one dashboard.

© 2026 InboxOne. All rights reserved.