Skip to main content
QUIETLYTIC
Email Security

DMARC Checker

Look up a domain’s DMARC record or paste one, and see what policy it actually applies.

Local · nothing leaves this browser Waiting for input
Esc Clear
Policy

Paste a DMARC record on the left.

How it works

DMARC does two things SPF and DKIM do not. It requires the domain that passed authentication to match the domain a reader actually sees in the From header, and it tells receivers what to do when nothing matches. Both live in a single TXT record at _dmarc on the domain.

Alignment is the mechanism, not the policy

A message can pass SPF on bounces.attacker.example while displaying your domain in From. DMARC discards that pass, because the authenticated domain does not align with the visible one. Relaxed alignment — the default for both adkim and aspf — accepts any subdomain of the same organisational domain; strict requires an exact match.

p=none and pct are where enforcement quietly disappears

p=none is a valid, correctly published DMARC record that protects nothing: failing mail is delivered as usual and a report is filed. It is the right first step and the wrong permanent state. pct= is the other half of the same problem — p=reject; pct=10 reads as enforcement and rejects one message in ten, with the other nine quarantined instead. Both are flagged here for that reason.

Paste a record, or look up a domain

A pasted record is read in your browser with no DNS query. Look up a domain fetches the TXT record at _dmarc.<domain> through Cloudflare's DNS-over-HTTPS resolver and analyses what is actually published — including the case where two DMARC records exist, which makes receivers ignore both. It does not follow a subdomain up to its organisational domain's policy, so look up the parent domain too when a subdomain has no record of its own. Lookups need a one-time bot check and are limited per hour.

To see what a specific message was judged against, read its Authentication-Results header with the Email Header Analyzer. DMARC passes only through an aligned SPF or DKIM pass, so the SPF Checker and DKIM Record Checker cover the other two records it depends on.

Example

v=DMARC1; p=reject; sp=none; rua=mailto:d@example.com enforces on the domain and explicitly exempts every subdomain, which is where spoofing moves next. v=DMARC1; p=quarantine is valid and gives you no reports at all, so there is no data behind the next policy change.

Frequently asked questions

What does p=none actually do?

Nothing to the mail. Failing messages are delivered as normal and the receiver files an aggregate report. It is the correct first step while reports are used to find legitimate senders, and no protection at all if left in place.

Why does pct= get flagged even on p=reject?

Because pct applies the policy to that share of failing mail and gives the rest the next weaker treatment. p=reject; pct=10 reads as enforcement and rejects one message in ten, quarantining the other nine.

What is the difference between relaxed and strict alignment?

Relaxed — the default for adkim and aspf — accepts any subdomain of the same organisational domain as the From address. Strict requires an exact match, which breaks any sender signing as a subdomain.

Why does a missing sp= tag matter?

It does not by itself: subdomains inherit p= when sp is absent. An sp= weaker than p= is the problem, because spoofing a subdomain is no harder and the record explicitly asks for it to be treated more leniently.

Can this check a domain’s published DMARC record?

Yes. Switch to "Look up domain", enter the domain, and the TXT record at _dmarc.<domain> is fetched and analysed. If more than one DMARC record is published, that is reported too: RFC 7489 says a receiver then applies none of them.

Related tools

From the intelligence desk