Check whether a domain has a valid DMARC policy published. See the effective policy, alignment and reporting settings, and catch configuration issues before they affect your email.
Loading tool access...
Every check turns the published policy record into a structured report
Identify the none, quarantine, or reject policy that applies to the domain and its subdomains.
Check whether SPF and DKIM use strict or relaxed alignment with the visible From domain.
Check aggregate and failure report addresses and external recipient permissions.
Confirm that the record is discoverable, correctly formatted, and sending reports to valid destinations.
Review the effective domain and subdomain settings before moving from none to quarantine or reject.
Check that the provider can pass aligned SPF or DKIM before applying a stricter DMARC policy.
Verify the rua destination, external authorization records, DNS response, and reporting URI syntax.
The policy communicates whether messages that fail DMARC should receive no special treatment, be treated as suspicious, or be rejected.
The alignment settings determine how closely the authenticated SPF or DKIM domain must match the visible From domain.
Reporting tags request aggregate data about mail streams and, optionally, detailed reports about individual failures.
The receiver evaluates SPF results and DKIM signatures to determine whether either authentication method passes.
DMARC checks if a passing SPF or DKIM domain aligns with the visible From domain before the receiver applies policy.
If neither method passes with alignment, the published policy asks the receiver to take no action, quarantine, or reject.
Publish a valid policy and configure aggregate reporting so legitimate and unauthorized sending sources can be identified
Ensure approved email platforms produce aligned SPF or DKIM results for the visible From domain
Move toward quarantine or reject after reviewing reports and confirming that legitimate mail streams authenticate correctly
Publishing more than one DMARC policy at the same DNS name prevents the records from being selected
A p=none policy without a valid rua address provides no aggregate reporting or deployment visibility.
SPF or DKIM may pass, but DMARC fails because the authenticated domain does not align with the visible From domain.
External rua or ruf domains may need to publish an authorization record before receivers can send reports to them
Automate end-to-end email testing with our APIs.