Хостинг в Україні від Mevcore

DMARC record generator

Build a DMARC record: policy, reports, SPF and DKIM alignment — with every parameter explained.

Separate multiple addresses with commas. Reports arrive once a day in XML format.

Few mail providers send them; they may contain fragments of messages.

Ready-to-use record

Type: TXT · Name: _dmarc.example.com

v=DMARC1; p=none

Add this TXT record to the domain's DNS zone. Changes take effect once the record's TTL expires — usually within a few minutes to an hour. Then verify the result with the DMARC check.

Why you need DMARC

SPF and DKIM verify the server and the signature, but they don't tell the receiver what to do when the check fails. DMARC closes this gap: the domain owner publishes a policy, and mail providers enforce it and send reports on all mail sent on the domain's behalf. Since 2024 Gmail and Yahoo require DMARC from everyone who sends bulk mail.

How to roll it out gradually

  1. p=none with an rua address — collect reports for a few weeks and identify every service that sends mail on your behalf. The DMARC report analyzer will help you make sense of the reports.
  2. Add all legitimate services to SPF and set up DKIM for them.
  3. p=quarantine, first with pct=25, then 100 — forged messages go to spam.
  4. p=reject — full protection: messages that fail the check are rejected.

Alignment

DMARC requires the domain in the “From” address to match the domain verified by SPF or DKIM. Relaxed alignment allows subdomains (news.example.com for example.com), strict alignment only an exact match. Relaxed is enough for most domains.

What should we call you?

Enter your name before starting the chat.

Hello! Type your question and an agent will reply as soon as possible.
Rate the agent’s reply