DMARC Policy Badge
DMARC tells receiving mail servers what to do with messages that claim to come from your domain but fail authentication. This badge reads your _dmarc record and shows the policy actually in force, including one inherited from a parent domain.
Live preview
Checked live by A2ZShowing the badge for a2z.tools. Enter your domain to see yours.
Embed code
The badge is re-checked automatically (every few hours; every 5 minutes for website status) and cached, so it adds almost nothing to your page load. The link carries rel="nofollow".
Works with
How it works
A2Z looks up the TXT record at _dmarc.your-domain and, if there is none, at the organisational domain found through the public suffix list - the same fallback receiving servers use. It parses the p= policy with the A2Z DMARC checker's code and reports it. When a subdomain has no record of its own, the report says which parent the policy came from, because that is often a surprise.
What is checked
- Record: TXT at _dmarc.<domain> beginning v=DMARC1; if absent, the organisational domain's record (RFC 7489 section 6.6.3)
- Green for p=reject or p=quarantine; amber for p=none or no record
Worked examples
Enforcing domain
Inputs: _dmarc.example.com: v=DMARC1; p=reject; rua=mailto:[email protected]
Result: Green: "p=reject"
Mail failing SPF and DKIM alignment is refused.
Subdomain without its own record
Inputs: mail.example.com has none; example.com has p=quarantine
Result: Green: "p=quarantine" (inherited from example.com)
The report names the parent the policy came from.
Limitations
- Does not read DMARC aggregate reports, so it cannot tell whether your legitimate mail passes.
- The pct= and sp= tags are shown in the report but do not change the badge colour.
- Some mailbox providers apply their own rules in addition to your published policy.
Where publishers use it
- Companies showing customers they protect against email spoofing
- Email deliverability consultants
- Security awareness pages
Questions
What does rua= in the record do?
It names the mailbox that receives daily aggregate reports from mailbox providers. Those reports are how you learn which services send mail as your domain before tightening the policy.
Is p=none bad?
It is monitoring mode: failures are reported to you but not blocked. It is the right first step while you check reports, which is why the badge shows it amber rather than red.
My subdomain shows a policy I did not set.
It is inherited from the parent (organisational) domain. The report shows where it came from so you can publish a record for the subdomain if you need a different policy.
Do I need SPF and DKIM too?
Yes. DMARC passes only when SPF or DKIM passes and aligns with the From domain, so it depends on at least one of them being set up correctly.
Sources
- RFC 7489 - DMARC - IETF . Policy discovery, including fallback to the organizational domain.
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools DMARC Policy Badge https://a2z.tools/dmarc-checker
<a href="https://a2z.tools/dmarc-checker">A2Z Tools DMARC Policy Badge</a>
[A2Z Tools DMARC Policy Badge](https://a2z.tools/dmarc-checker)
DMARC Policy Badge by A2Z Tools - https://a2z.tools/dmarc-checker
Related widgets
-
Shows whether your domain publishes an SPF record and how it ends (-all, ~all).
-
Checks a domain's SPF and DMARC records and DNSSEC status in one go.
-
Shows whether your domain is DNSSEC-signed and validates.
-
A live badge showing that your SSL certificate is valid, trusted and how many days it has left.
-
A badge counting down the days until your SSL certificate expires.
-
Shows whether your site serves HTTPS and redirects plain-HTTP visitors to it.