Daily Website Report
Free tool

DMARC Record Generator

Build a DMARC record for Google Workspace, Microsoft 365 (Office 365) or any other email provider. Choose your options, copy the record, and publish it as a TXT record. Free, no signup.

Your DMARC record

Add this as a TXT record at your DNS provider (where you manage your domain, such as Cloudflare, GoDaddy, Namecheap or your web host).

Type: TXT · Name/Host: _dmarc
v=DMARC1; p=none; fo=1
  • p=none only monitors: failing mail is still delivered. That is the right start. Move to quarantine, then reject, after two to four weeks of reports show all your legitimate mail passing.
  • No report address, so you won't get the daily reports that show who is sending as your domain. Add a mailbox you read (for example dmarc@yourdomain.com) and create it first.

Published it? Check that it worked

DNS changes usually show up within minutes. Run the checker to confirm your DMARC, SPF and DKIM records are all in place.

Check my domain →

What each part of the record means

TagWhat it does
v=DMARC1The version. Always first, always DMARC1.
p=The policy for mail that fails: none (just report), quarantine (spam folder) or reject (refuse).
rua=Where receivers send daily aggregate reports, written as mailto:address.
pct=The share of failing mail the policy applies to. Useful for easing into quarantine or reject.
sp=A separate policy for subdomains. Left out, subdomains follow p.
fo=When to generate failure reports: 1 means whenever SPF or DKIM fails.
adkim= / aspf=How closely the domain in the visible From address must match the DKIM and SPF domains. Relaxed allows subdomains; strict does not.

DMARC for Google Workspace and Office 365

DMARC is the same record for every email provider, but it only passes if SPF and DKIM are set up first. Follow the provider steps, then publish the record you generated above:

A safe rollout, step by step

  1. Generate a record with p=none and a report address you read, and publish it.
  2. For two to four weeks, read the reports. They list every server sending mail as your domain, including ones you forgot about.
  3. Add SPF or DKIM for each legitimate sender until its mail passes.
  4. Generate a new record with p=quarantine, optionally pct=25 first, and replace the old one. Never add a second.
  5. Raise pct to 100, watch for problems, then move to p=reject.

Frequently asked questions

What does a DMARC record look like?

A DMARC record is a single line of text, for example v=DMARC1; p=none; rua=mailto:dmarc@example.com; fo=1. It is published as a TXT record at _dmarc.yourdomain.com. The v tag is the version, p is the policy for mail that fails authentication, and rua is where receivers send their reports.

Which DMARC policy should I choose?

Start with p=none and a report address, and keep it for two to four weeks while the reports show you every service that sends mail as your domain. When all legitimate mail passes, move to p=quarantine, then p=reject. Choosing quarantine or reject too early can send your own invoices and newsletters to spam.

Where do I add the DMARC record?

In the DNS settings for your domain, at your domain registrar or DNS host (Cloudflare, GoDaddy, Namecheap, your web host). Add a TXT record with the name _dmarc and the generated line as the value. Some providers want the full name _dmarc.yourdomain.com and some add the domain for you.

Do I need a DMARC record for Google Workspace or Office 365?

Yes. Google Workspace and Microsoft 365 (formerly Office 365) do not publish DMARC for your domain, so you add it yourself. It builds on SPF and DKIM, which you also switch on in the Google Admin console or the Microsoft Defender portal.

Can I have more than one DMARC record?

No. A domain must have exactly one DMARC record at _dmarc.yourdomain.com. If there are two, receivers ignore both. To change your policy, edit the existing record instead of adding another.

What is the rua address for?

rua is where receivers such as Google, Microsoft and Yahoo send their daily aggregate reports about mail claiming to be from your domain. They are XML files, so they are easiest to read through a free report reader, and you must be able to receive mail at that address.