DMARC record generator

Build a DMARC record with a staged rollout in mind - this warns before recommending full enforcement.

1 · Policy

2 · Alignment & reporting

3 · Result

Publish this as a TXT record at _dmarc.yourdomain.com, then verify with the DMARC checker.


Why this does not just tell you to pick reject

Moving straight to p=reject without first confirming every legitimate source of your domain's mail passes SPF or DKIM alignment can silently block real mail - your own marketing platform, a forwarding arrangement, or a service you forgot was sending on your behalf. This generator warns about that rather than defaulting everyone to the strictest setting.

The staged rollout this recommends

  1. p=none with an rua= address - pure monitoring. Nothing is blocked; you just start receiving aggregate reports showing what would happen.
  2. p=quarantine once the reports show your legitimate mail is aligning correctly - failures go to spam rather than being rejected outright.
  3. p=reject last, once quarantine has run cleanly for a period - full enforcement.

The pct= tag can also ramp up gradually within a stage, applying the policy to only a percentage of mail at first.

Alignment: relaxed vs strict

Relaxed alignment (the default) accepts a matching organizational domain even if the exact subdomain differs between the visible From address and the authenticating domain. Strict alignment requires an exact match. Relaxed is the more forgiving, more commonly used setting; strict is for domains that need tighter guarantees and have verified every sender complies.

After generating

Publish the result at _dmarc.yourdomain.com, then verify with the DMARC checker.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.