Trusted by over 40,000+ domain owners, sales reps & engineers worldwide
What is a DMARC record?
A DMARC (Domain-based Message Authentication, Reporting, and Conformance) record is a DNS TXT entry published under _dmarc.yourdomain.com. It instructs receiving mail transfer agents (like Gmail, Microsoft 365, and Yahoo) on how to handle emails that fail SPF or DKIM authentication.
Without a published DMARC record, cybercriminals can easily forge your domain name in phishing attacks, damaging your domain reputation and causing your legitimate cold outreach and marketing emails to be blacklisted.
How to Create a DMARC Record in 3 Steps
p=none for monitoring) and add your reporting email address._dmarc and paste the generated value.p=quarantine or p=reject.Frequently Asked Questions
Everything you need to know about RFC 7489 syntax, policy enforcement, and 2026 inbox deliverability.
| Tag | Tag Explanation |
|---|---|
| v=DMARC1 | Protocol version identifier. Must be the first tag in the TXT record. |
| p | Policy for the organizational domain. Valid values: none (monitoring), quarantine, reject. |
| rua | Mailto URI list for aggregate feedback reports (e.g. rua=mailto:dmarc@yourdomain.com). |
| ruf | Mailto URI list for message-specific forensic failure reports. |
| sp | Subdomain policy. Applies policy to all subdomains of the root domain. |
| pct | Percentage of messages from 1 to 100 to subject to policy enforcement. |
| adkim | DKIM alignment mode. "r" for relaxed (subdomains pass), "s" for strict. |
| aspf | SPF alignment mode. "r" for relaxed, "s" for strict. |
| fo | Forensic reporting options. 0 (all mechanisms fail), 1 (any fail), d (DKIM fail), s (SPF fail). |