DMARC Record Generator

Build a valid DMARC record and protect your domain from spoofing.

Pick your policy and reporting options, and we assemble a copy-ready DMARC TXT record for your DNS.
Every tag is explained in plain English, so you know exactly what you’re publishing.

Optional. We use it to build the DNS host name (_dmarc.yourdomain.com). It never leaves your browser.
Policy
Tells receivers what to do with messages that fail DMARC. Start with none to monitor, then tighten to quarantine and reject.
Overrides the policy for subdomains. Leave it inherited unless subdomains need different handling.
The share of failing messages the policy applies to, from 0 to 100. Ramp up gradually when you first enforce a strict policy.
Reporting
Where daily aggregate reports are sent. We add the mailto: prefix for you. Use these reports to see who sends on your behalf.
Where per-message failure reports are sent. Many providers no longer send these, so it’s optional.
How often aggregate reports are generated, in seconds. The default is 86400 (once a day).
Controls when forensic reports are generated. 1 is the most thorough.
The format for forensic reports. Almost everyone uses afrf, the default.
Alignment
How strictly the DKIM domain must match your domain. Relaxed allows subdomains; strict requires an exact match.
How strictly the SPF domain must match your domain. Relaxed allows subdomains; strict requires an exact match.
DNS host name _dmarc.yourdomain.com Your DMARC record
v=DMARC1; p=none
Rather not touch DNS yourself? Have Hunter configure it

Trusted by more than 7,000,000 professionals to find and reach their customers

  • Semrush
  • Vimeo
  • Cisco
  • Canva
  • Customer.io

How to create your DMARC record

Choose your policy

Start with a monitoring policy (p=none) to watch your traffic without affecting delivery, then tighten to quarantine or reject once you’re confident.

Add your reporting addresses

Enter an address to receive aggregate reports (rua). These reports show you every source sending as your domain, so you can spot spoofing and misconfigured senders.

Copy your record

We assemble a valid DMARC TXT record as you go. Copy it, then create a TXT record at the host _dmarc.yourdomain.com in your DNS settings.

Publish and verify it’s live

Save the record with your DNS provider, wait for it to propagate, then confirm your setup with the Email Deliverability Checker to make sure DMARC, SPF, and DKIM all pass.

Skip the DNS guesswork

DMARC only works when SPF, DKIM, and DMARC line up, and getting there by hand across your DNS is fiddly and easy to break. Stop wrestling with DNS records. Connect your domain to Hunter and we help you get email authentication set up so your emails land in the inbox.

Set up your domain

Why DMARC matters for your emails

DMARC ties SPF and DKIM together into a policy receivers can act on. It’s the difference between hoping your emails land and knowing they do.

Land in the inbox

Gmail and Yahoo now require DMARC for bulk senders. A valid record keeps your emails out of spam and delivered.

Stop email spoofing

DMARC tells receivers to reject messages that fake your domain, protecting your brand from phishing and impersonation.

See who sends as you

Aggregate reports reveal every service sending on your behalf, so you catch unauthorized senders before they hurt your reputation.

Frequently asked questions

Everything you need to know about DMARC records and how to set them up.

A DMARC record is a DNS TXT record that tells receiving mail servers how to handle emails that claim to come from your domain but fail authentication. It builds on SPF and DKIM, adds a policy (monitor, quarantine, or reject), and can send you reports on who’s sending as your domain. It’s published at the host _dmarc.yourdomain.com.

Choose a policy above (start with p=none to monitor), add an address to receive aggregate reports, and copy the generated record. Then create a TXT record in your DNS settings with the host _dmarc.yourdomain.com and paste the record as its value. Save it and it goes live once DNS propagates.

A safe starting point is v=DMARC1; p=none; rua=mailto:you@yourdomain.com. This monitors your traffic without affecting delivery and sends you daily reports. Once the reports confirm your legitimate senders pass DMARC, tighten the policy to quarantine and then reject.

The policy tag p tells receivers what to do with messages that fail DMARC. none takes no action and only monitors, quarantine sends failing messages to spam, and reject blocks them outright. The usual path is to start at none, review your reports, then move to quarantine and finally reject.

Yes. DMARC checks that a message passes SPF or DKIM and that the passing domain aligns with your domain, so both should be in place first. Build your SPF record with the SPF Record Generator, set up DKIM with your email provider, then add DMARC on top.

Publish it as a TXT record at the host _dmarc.yourdomain.com in your DNS provider’s settings (the same place you manage your other DNS records). The value is the full record generated above. Only one DMARC record is allowed per domain.

Yes, completely free with no signup and no limits. If you’d rather not manage DNS by hand, you can create a free Hunter account and we help you get email authentication set up for your sending domain.

After you publish the record and DNS propagates, run your domain through the Email Deliverability Checker to confirm DMARC, SPF, and DKIM all pass. Your aggregate reports (rua) will also start arriving, showing you every source sending as your domain.

The rua tag sets the address for aggregate reports, which are daily summaries of the messages sent as your domain and whether they passed authentication. The ruf tag sets the address for forensic reports, which are per-message failure samples. Aggregate reports are the most useful, and many providers no longer send forensic reports.

SPF lists the servers allowed to send email for your domain, DKIM signs your messages so receivers can verify they weren’t tampered with, and DMARC ties the two together with a policy and reporting. All three work together to prove your emails are genuine. Use the SPF Record Generator to build your SPF record alongside this one.

Once you save the TXT record, it typically propagates within a few minutes to a few hours, depending on your DNS provider and the record’s TTL. After that, receiving servers start applying your policy and your aggregate reports begin arriving within a day.

We use cookies
We use cookies to analyze how Hunter's website is used and personalize your experience. Learn more