DMARC Policy Badge

DMARC tells receiving mail servers what to do with messages that claim to come from your domain but fail authentication. This badge reads your _dmarc record and shows the policy actually in force, including one inherited from a parent domain.

Website & Security SVG badge Checked by A2Z server Free · no ads

Customize your badge

The badge is checked for this domain. Enter the site you will show it on.
Style
Colours
Size

Live preview

Checked live by A2Z
DMARC Policy Badge for a2z.tools

Showing the badge for a2z.tools. Enter your domain to see yours.

Embed code

The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".

Works with

How it works

A2Z looks up the TXT record at _dmarc.your-domain and, if there is none, at the organisational domain found through the public suffix list - the same fallback receiving servers use. It parses the p= policy with the A2Z DMARC checker's code and reports it. When a subdomain has no record of its own, the report says which parent the policy came from, because that is often a surprise.

What is checked

  • Record: TXT at _dmarc.<domain> beginning v=DMARC1; if absent, the organisational domain's record (RFC 7489 section 6.6.3)
  • Green for p=reject or p=quarantine; amber for p=none or no record

Worked examples

Enforcing domain

Inputs: _dmarc.example.com: v=DMARC1; p=reject; rua=mailto:[email protected]

Result: Green: "p=reject"

Mail failing SPF and DKIM alignment is refused.

Subdomain without its own record

Inputs: mail.example.com has none; example.com has p=quarantine

Result: Green: "p=quarantine" (inherited from example.com)

The report names the parent the policy came from.

Limitations

  • Does not read DMARC aggregate reports, so it cannot tell whether your legitimate mail passes.
  • The pct= and sp= tags are shown in the report but do not change the badge colour.
  • Some mailbox providers apply their own rules in addition to your published policy.

Where publishers use it

  • Companies showing customers they protect against email spoofing
  • Email deliverability consultants
  • Security awareness pages

Questions

What does rua= in the record do?

It names the mailbox that receives daily aggregate reports from mailbox providers. Those reports are how you learn which services send mail as your domain before tightening the policy.

Is p=none bad?

It is monitoring mode: failures are reported to you but not blocked. It is the right first step while you check reports, which is why the badge shows it amber rather than red.

My subdomain shows a policy I did not set.

It is inherited from the parent (organisational) domain. The report shows where it came from so you can publish a record for the subdomain if you need a different policy.

Do I need SPF and DKIM too?

Yes. DMARC passes only when SPF or DKIM passes and aligns with the From domain, so it depends on at least one of them being set up correctly.

Sources

  1. RFC 7489 - DMARC - IETF . Policy discovery, including fallback to the organizational domain.

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools DMARC Policy Badge
https://a2z.tools/dmarc-checker

Preview