Free Tool · Runs in your browser

DMARC Record Generator

Set your policy, subdomain policy, aggregate and forensic report addresses, alignment modes and rollout percentage. We assemble the record, validate it and show exactly where to publish it.

  • 100% free
  • No signup
  • Nothing leaves your browser

DMARC Record Generator

Used for the DNS host name and to spot external reporting addresses.

Monitor only. Nothing is blocked. You receive reports showing who sends as your domain. The right starting point.

Leave on Inherit unless subdomains need a different rule. Reject here stops spoofing of subdomains you never use.

Comma separated. Daily XML summaries of who is sending as your domain. Use a DMARC report service or a dedicated mailbox.

Optional. Per-message failure samples. Few receivers send these, and they can contain message content.

100%

Relaxed accepts subdomains of the From domain.

Strict requires an exact domain match.

Only used when ruf is set.

Default 86400 (daily). Most receivers ignore other values.

Policy

p=none

Monitor only

Applies to

100%

All mail

Reporting

Off

No aggregate reports

DMARC record
v=DMARC1; p=none

Publish this DNS record

Add it at your DNS host for yourdomain.com

HostTypeTTLValue
_dmarcTXT3600v=DMARC1; p=none

The full host name is _dmarc.yourdomain.com. Some DNS panels want that full name, others just _dmarc. A domain may have only one DMARC record.

Rollout: monitoring phase

  • p=none blocks nothing. Its job is to collect reports so you can see every source sending as your domain.
  • Add every legitimate source to SPF and make sure each one signs with DKIM aligned to your domain.
  • When reports show only your own senders passing for a few weeks, move to p=quarantine with pct=10 to 25, then raise it.

Checks

No aggregate report address

Without rua you get no visibility into who is sending as your domain, so you cannot safely move past p=none. Add at least one mailbox or a DMARC report service.

p=none provides no protection

Fine to start. Spoofed mail is still delivered normally; the record only enables reporting. Plan to reach quarantine or reject.

Relaxed alignment

Subdomains of the From domain count as aligned. This is the default and works with Google Workspace, Microsoft 365 and most ESPs.

Once published, confirm it with the DMARC checker. DMARC only passes if SPF or DKIM aligns with your From domain, so set those up first.

How It Works

Three steps, no account needed

  1. 1

    Choose a policy

    Start with p=none to collect reports, or pick quarantine or reject if SPF and DKIM already pass and align for every sender.

  2. 2

    Add reporting

    Enter at least one rua address so receivers send you daily aggregate reports. Adjust alignment, subdomain policy and percentage if you need to.

  3. 3

    Publish on _dmarc

    Copy the record, create a TXT record at _dmarc.yourdomain.com, then confirm it with the DMARC checker.

Record & Asset Generators

What DMARC adds on top of SPF and DKIM

SPF and DKIM each prove something about a message, but neither checks that the proof relates to the address the recipient actually sees. DMARC closes that gap: it requires SPF or DKIM to pass and to align with the From domain, then tells receivers what to do when both fail. It also sends you reports, which is the only reliable way to discover every tool sending as your domain.

The record lives at _dmarc.yourdomain.com as a TXT record. A minimal, useful one looks like this.

v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com

Choosing between none, quarantine and reject

p=none is a monitoring mode: nothing changes for recipients, but you receive reports. p=quarantine asks receivers to put failing mail in spam. p=reject asks them to refuse it. Gmail and Yahoo require a DMARC record from bulk senders and treat enforcement (quarantine or reject) as a sign of a well-run domain.

  • New domains that only send from one mailbox provider with DKIM can usually go straight to p=reject.
  • Domains with a history of tools and integrations should start at p=none and read reports for a few weeks.
  • Use pct to phase in enforcement: pct=25 applies the policy to a quarter of failing mail and the weaker policy to the rest.
  • Set sp=reject when subdomains never send mail, so nobody can spoof them either.

Aggregate and forensic reports

The rua tag lists where receivers send aggregate reports: daily XML files summarising every IP that sent as your domain, and whether SPF and DKIM passed and aligned. The ruf tag requests forensic reports, per-message samples that few receivers still send and that can contain message content. For most teams, rua alone is enough.

If the report address is on a different domain than the one publishing the record, the receiving domain must publish an authorisation record at yourdomain.com._report._dmarc.reportdomain.com containing v=DMARC1. Hosted DMARC report services do this automatically.

Alignment modes and cold email tools

Relaxed alignment (the default) accepts a DKIM signing domain or SPF envelope domain that is the From domain or one of its subdomains. Strict requires an exact match. Cold email platforms send through your own mailbox provider, so the From domain, DKIM domain and SPF domain match and relaxed alignment passes cleanly.

Problems appear when a tool sends from its own infrastructure with a different envelope domain and no custom DKIM; the message fails alignment and an enforcing policy quarantines it. Check the reports before tightening, and keep alignment relaxed unless you have a specific reason. InboxOne domains come with a DMARC record already in place so the first campaign starts authenticated.

FAQ

Frequently asked questions

Still stuck? Book a 30-minute deliverability call and we'll look at your setup together.

Publish v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com first, confirm SPF and DKIM pass and align in the reports, then move to p=quarantine and finally p=reject. Cold email domains sending only through Google Workspace or Microsoft 365 with DKIM enabled can usually reach reject within a few weeks.

Create a TXT record with the host name _dmarc (some providers want the full _dmarc.yourdomain.com) and paste the record as the value. Use the default TTL. A domain may have only one DMARC record, so edit any existing one rather than adding a second.

It is optional in the specification but essential in practice. Without rua you get no reports, so you cannot see which senders fail alignment or safely tighten the policy. Use a dedicated mailbox or a DMARC reporting service that parses the XML for you.

pct is the percentage of failing messages the policy applies to. With p=quarantine and pct=20, one in five failing messages is quarantined and the rest are treated as p=none. It lets you phase in enforcement. It has no effect when the policy is none.

Relaxed for almost everyone. It lets subdomains of your From domain count as aligned, which is how most mailbox providers and ESPs sign mail. Strict requires an exact match and mainly benefits organisations that tightly control every sending domain and want no subdomain leeway.

DMARC needs SPF to align, not just pass. If the envelope-from domain belongs to your ESP rather than your domain, SPF passes for the ESP but does not align, and DMARC falls back to DKIM. Fix it by enabling custom DKIM signing at the provider or using a custom return-path domain.

Ready to Scale Your Outbound?

Your Cold Email Infrastructure Shouldn't Be the Bottleneck.

Domains, mailboxes, DNS, deliverability, and platform exports — all from one dashboard. Starting at $39/month for 10 production-ready mailboxes.

Inbox One Logo

Cold email infrastructure platform. Buy domains, provision Google Workspace mailboxes, auto-configure DNS, and export to 5 outreach platforms — all from one dashboard.

© 2026 InboxOne. All rights reserved.