Free toolAPI available

DMARC record checker

Check whether a domain has a valid DMARC policy published. See the effective policy, alignment and reporting settings, and catch configuration issues before they affect your email.

Loading tool access...

interacjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunioninteracjohnsoncontrolsapolloverorbimercksalesforceworkdayatlassianpbstoyotaadobemediumcartaoptimizelysapxeroxassabloyenvatophilipstransunion

What the DMARC checker analyzes

Every check turns the published policy record into a structured report

Policy and enforcement

Identify the none, quarantine, or reject policy that applies to the domain and its subdomains.

Authentication alignment

Check whether SPF and DKIM use strict or relaxed alignment with the visible From domain.

Reporting configuration

Check aggregate and failure report addresses and external recipient permissions.

When to check a DMARC record

When first publishing DMARC

Confirm that the record is discoverable, correctly formatted, and sending reports to valid destinations.

Before changing the policy

Review the effective domain and subdomain settings before moving from none to quarantine or reject.

When adding an email provider

Check that the provider can pass aligned SPF or DKIM before applying a stricter DMARC policy.

When reports stop arriving

Verify the rua destination, external authorization records, DNS response, and reporting URI syntax.

What a DMARC record can tell you

How failures should be handled

The policy communicates whether messages that fail DMARC should receive no special treatment, be treated as suspicious, or be rejected.

Which identities must align

The alignment settings determine how closely the authenticated SPF or DKIM domain must match the visible From domain.

Where reports should be sent

Reporting tags request aggregate data about mail streams and, optionally, detailed reports about individual failures.

How DMARC authentication works

1. SPF and DKIM are evaluated

The receiver evaluates SPF results and DKIM signatures to determine whether either authentication method passes.

2. Check domain alignment

DMARC checks if a passing SPF or DKIM domain aligns with the visible From domain before the receiver applies policy.

3. The published policy is considered

If neither method passes with alignment, the published policy asks the receiver to take no action, quarantine, or reject.

Deploying DMARC safely

Start with visibility and reporting

Publish a valid policy and configure aggregate reporting so legitimate and unauthorized sending sources can be identified

Fix authentication and alignment

Ensure approved email platforms produce aligned SPF or DKIM results for the visible From domain

Strengthen the policy deliberately

Move toward quarantine or reject after reviewing reports and confirming that legitimate mail streams authenticate correctly

Common DMARC issues

Multiple DMARC records

Publishing more than one DMARC policy at the same DNS name prevents the records from being selected

Monitoring without reports

A p=none policy without a valid rua address provides no aggregate reporting or deployment visibility.

SPF or DKIM misalignment

SPF or DKIM may pass, but DMARC fails because the authenticated domain does not align with the visible From domain.

Unauthorized report destinations

External rua or ruf domains may need to publish an authorization record before receivers can send reports to them

Signup for testmail.app

Automate end-to-end email testing with our APIs.

FAQ

What is a DMARC checker?

A DMARC checker finds and analyzes the email-authentication policy published for a domain. It shows the effective policy, SPF and DKIM alignment settings, reporting destinations, subdomain rules, and any DNS or configuration problems. It validates the policy record, but it does not determine whether a specific email passed DMARC.

How do I check a DMARC record?

Enter the domain you want to check. The tool will look for the applicable DMARC policy, normally beginning at _dmarc.example.com, and show the published record, effective policy, alignment rules, reporting settings, inherited values, and any errors or warnings.

What makes a DMARC record valid?

A valid DMARC record must be the only DMARC policy record at its DNS name, begin with v=DMARC1, and use valid tag syntax and values. The version tag must appear first and is case-sensitive. A valid record can still use a non-enforcing policy or contain settings that require review.

What do p=none, p=quarantine, and p=reject mean?

These values communicate the domain owner’s requested handling preference for messages that fail DMARC. none requests no special treatment, quarantine identifies failures as suspicious, and reject identifies the failed use of the domain as invalid. Receiving systems can consider other information when making the final delivery decision.

How does DMARC work with SPF and DKIM?

DMARC uses the results of SPF and DKIM and compares their authenticated domains with the domain visible in the email’s From address. A message passes DMARC when at least one supported mechanism passes and its authenticated domain aligns with the visible From domain.

Why can DMARC fail when SPF or DKIM passes?

DMARC can fail when SPF or DKIM passes but the authenticated domain does not align with the visible From domain. For example, SPF may authenticate a provider-controlled Return-Path domain, or DKIM may use a signing domain belonging to a third-party service.

Does a valid DMARC record stop spoofing or guarantee delivery?

No, a valid DMARC record does not prevent every form of impersonation or guarantee that legitimate messages will be delivered. DMARC helps receiving systems evaluate unauthorized use of the exact From domain, but delivery can also depend on authentication results, reputation, message content, forwarding, receiver policy, and other filtering signals.