Daily Website Report
Free tool

DMARC Checker

Check the DMARC, SPF and DKIM records of any domain in seconds. See what's wrong and copy the exact record that fixes it. Free, no signup.

What is DMARC?

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that protects your domain from being used in phishing and spoofed email. It builds on two older checks:

  • SPF lists the servers allowed to send mail for your domain.
  • DKIM adds a cryptographic signature proving a message wasn't altered and really came from you.

DMARC tells receiving servers what to do when a message fails both, and sends you reports on who is sending mail as your domain. Without it, a failing SPF or DKIM check is often ignored. Since 2024, Gmail and Yahoo require DMARC from bulk senders, and missing it is one of the most common reasons business email lands in spam.

DMARC policies explained

PolicyWhat happens to failing mailWhen to use it
p=noneDelivered normally; you only get reportsThe first 2–4 weeks, while you find every service sending as you
p=quarantineSent to the spam folderOnce your reports show legitimate mail passing
p=rejectRefused outrightFull protection; the goal for every domain

How to add a DMARC record

  1. Log in to wherever your domain's DNS is managed (Cloudflare, GoDaddy, Namecheap, your web host…).
  2. Add a new TXT record with the name/host _dmarc.
  3. Paste the value v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com; fo=1, using an address you can read.
  4. Save, wait a few minutes, and run this checker again.
  5. After a few weeks of clean reports, change p=none to p=quarantine, then p=reject.

Google Workspace

SPF should include include:_spf.google.com. Turn on DKIM in the Admin console under Apps → Google Workspace → Gmail → Authenticate email, publish the TXT record it gives you (selector google), then click Start authentication.

Microsoft 365

SPF should include include:spf.protection.outlook.com. Enable DKIM in the Microsoft Defender portal under Email authentication settings, and add the two CNAME records it shows (selector1._domainkey and selector2._domainkey).

Newsletters and other senders

Every other service that sends mail as you, such as Mailchimp, HubSpot, your CRM or your website's contact form, needs to be in your SPF record or signing with DKIM for your domain. Otherwise it will fail once you move to p=quarantine. DMARC reports show you which services those are.

Frequently asked questions

What is a DMARC record?

A DMARC record is a TXT record published at _dmarc.yourdomain.com. It tells receiving mail servers what to do with email that claims to be from your domain but fails SPF and DKIM checks (deliver it, send it to spam, or reject it) and where to send reports about it.

Do I need DMARC if I already have SPF and DKIM?

Yes. SPF and DKIM only produce a pass or fail result. DMARC is what tells receivers to act on a failure, and it checks that the domain in the visible From address matches. Since 2024, Gmail and Yahoo require a DMARC record from anyone sending bulk mail, and missing DMARC hurts inbox placement for everyone else too.

Which DMARC policy should I use?

Start with p=none and a rua reporting address for two to four weeks, so you can see every service that sends mail as you. Once all legitimate mail passes, move to p=quarantine, then p=reject. Domains that never send email can go straight to p=reject.

Why does the checker say no DKIM was found when I have DKIM?

DKIM keys live under a selector (selector._domainkey.yourdomain.com) and DNS has no way to list them, so we try the selectors used by the major providers. If yours uses a custom selector, find it in the s= value of the DKIM-Signature header on an email you sent.

How long does a DMARC change take to show up?

Usually a few minutes, up to the TTL of the record (often an hour). This checker caches each result for 5 minutes, so re-check shortly after publishing.