Choose your policy
Start with a monitoring policy (p=none) to watch your traffic without affecting delivery, then tighten to quarantine or reject once you’re confident.
Pick your policy and reporting options, and we assemble a copy-ready DMARC TXT record for your DNS.
Every tag is explained in plain English, so you know exactly what you’re publishing.
_dmarc.yourdomain.com
Your DMARC record
v=DMARC1; p=none
Start with a monitoring policy (p=none) to watch your traffic without affecting delivery, then tighten to quarantine or reject once you’re confident.
Enter an address to receive aggregate reports (rua). These reports show you every source sending as your domain, so you can spot spoofing and misconfigured senders.
We assemble a valid DMARC TXT record as you go. Copy it, then create a TXT record at the host _dmarc.yourdomain.com in your DNS settings.
Save the record with your DNS provider, wait for it to propagate, then confirm your setup with the Email Deliverability Checker to make sure DMARC, SPF, and DKIM all pass.
DMARC only works when SPF, DKIM, and DMARC line up, and getting there by hand across your DNS is fiddly and easy to break. Stop wrestling with DNS records. Connect your domain to Hunter and we help you get email authentication set up so your emails land in the inbox.
Set up your domainDMARC ties SPF and DKIM together into a policy receivers can act on. It’s the difference between hoping your emails land and knowing they do.
Gmail and Yahoo now require DMARC for bulk senders. A valid record keeps your emails out of spam and delivered.
DMARC tells receivers to reject messages that fake your domain, protecting your brand from phishing and impersonation.
Aggregate reports reveal every service sending on your behalf, so you catch unauthorized senders before they hurt your reputation.
Everything you need to know about DMARC records and how to set them up.
A DMARC record is a DNS TXT record that tells receiving mail servers how to handle emails that claim to come from your domain but fail authentication. It builds on SPF and DKIM, adds a policy (monitor, quarantine, or reject), and can send you reports on who’s sending as your domain. It’s published at the host _dmarc.yourdomain.com.
Choose a policy above (start with p=none to monitor), add an address to receive aggregate reports, and copy the generated record. Then create a TXT record in your DNS settings with the host _dmarc.yourdomain.com and paste the record as its value. Save it and it goes live once DNS propagates.
A safe starting point is v=DMARC1; p=none; rua=mailto:you@yourdomain.com. This monitors your traffic without affecting delivery and sends you daily reports. Once the reports confirm your legitimate senders pass DMARC, tighten the policy to quarantine and then reject.
The policy tag p tells receivers what to do with messages that fail DMARC. none takes no action and only monitors, quarantine sends failing messages to spam, and reject blocks them outright. The usual path is to start at none, review your reports, then move to quarantine and finally reject.
Yes. DMARC checks that a message passes SPF or DKIM and that the passing domain aligns with your domain, so both should be in place first. Build your SPF record with the SPF Record Generator, set up DKIM with your email provider, then add DMARC on top.
Publish it as a TXT record at the host _dmarc.yourdomain.com in your DNS provider’s settings (the same place you manage your other DNS records). The value is the full record generated above. Only one DMARC record is allowed per domain.
Yes, completely free with no signup and no limits. If you’d rather not manage DNS by hand, you can create a free Hunter account and we help you get email authentication set up for your sending domain.
After you publish the record and DNS propagates, run your domain through the Email Deliverability Checker to confirm DMARC, SPF, and DKIM all pass. Your aggregate reports (rua) will also start arriving, showing you every source sending as your domain.
The rua tag sets the address for aggregate reports, which are daily summaries of the messages sent as your domain and whether they passed authentication. The ruf tag sets the address for forensic reports, which are per-message failure samples. Aggregate reports are the most useful, and many providers no longer send forensic reports.
SPF lists the servers allowed to send email for your domain, DKIM signs your messages so receivers can verify they weren’t tampered with, and DMARC ties the two together with a policy and reporting. All three work together to prove your emails are genuine. Use the SPF Record Generator to build your SPF record alongside this one.
Once you save the TXT record, it typically propagates within a few minutes to a few hours, depending on your DNS provider and the record’s TTL. After that, receiving servers start applying your policy and your aggregate reports begin arriving within a day.