DMARC Checker
Look up a domain’s DMARC record or paste one, and see what policy it actually applies.
Checking for an existing session…
Paste a DMARC record on the left.
How it works
DMARC does two things SPF and DKIM do not. It requires the domain that passed authentication to match the domain a
reader actually sees in the From header, and it tells receivers what to do when nothing matches. Both live in a
single TXT record at _dmarc on the domain.
Alignment is the mechanism, not the policy
A message can pass SPF on bounces.attacker.example while displaying your domain in From. DMARC
discards that pass, because the authenticated domain does not align with the visible one. Relaxed alignment — the
default for both adkim and aspf — accepts any subdomain of the same organisational
domain; strict requires an exact match.
p=none and pct are where enforcement quietly disappears
p=none is a valid, correctly published DMARC record that protects nothing: failing mail is delivered
as usual and a report is filed. It is the right first step and the wrong permanent state.
pct= is the other half of the same problem — p=reject; pct=10 reads as enforcement and
rejects one message in ten, with the other nine quarantined instead. Both are flagged here for that reason.
Paste a record, or look up a domain
A pasted record is read in your browser with no DNS query. Look up a domain fetches the TXT
record at _dmarc.<domain> through Cloudflare's DNS-over-HTTPS resolver and analyses what is
actually published — including the case where two DMARC records exist, which makes receivers ignore both. It does
not follow a subdomain up to its organisational domain's policy, so look up the parent domain too when a subdomain
has no record of its own. Lookups need a one-time bot check and are limited per hour.
To see what a specific message was judged against, read its Authentication-Results header with the Email Header Analyzer. DMARC passes only through an aligned SPF or DKIM pass, so the SPF Checker and DKIM Record Checker cover the other two records it depends on.
Example
v=DMARC1; p=reject; sp=none; rua=mailto:d@example.com enforces on the domain and explicitly exempts
every subdomain, which is where spoofing moves next. v=DMARC1; p=quarantine is valid and gives you no
reports at all, so there is no data behind the next policy change.
Frequently asked questions
What does p=none actually do?
Nothing to the mail. Failing messages are delivered as normal and the receiver files an aggregate report. It is the correct first step while reports are used to find legitimate senders, and no protection at all if left in place.
Why does pct= get flagged even on p=reject?
Because pct applies the policy to that share of failing mail and gives the rest the next weaker treatment. p=reject; pct=10 reads as enforcement and rejects one message in ten, quarantining the other nine.
What is the difference between relaxed and strict alignment?
Relaxed — the default for adkim and aspf — accepts any subdomain of the same organisational domain as the From address. Strict requires an exact match, which breaks any sender signing as a subdomain.
Why does a missing sp= tag matter?
It does not by itself: subdomains inherit p= when sp is absent. An sp= weaker than p= is the problem, because spoofing a subdomain is no harder and the record explicitly asks for it to be treated more leniently.
Can this check a domain’s published DMARC record?
Yes. Switch to "Look up domain", enter the domain, and the TXT record at _dmarc.<domain> is fetched and analysed. If more than one DMARC record is published, that is reported too: RFC 7489 says a receiver then applies none of them.
Related tools
SPF Checker
Look up a domain’s SPF record or paste one, and see every mechanism explained and counted.
Partly sends dataDKIM Record Checker
Look up the DKIM key at a selector, or read a DKIM-Signature header and key record tag by tag.
Partly sends dataMX Lookup
See where a domain’s mail is delivered, in priority order, with its SPF and DMARC status beside it.
Sends dataEmail Header Analyzer
Read a raw email header as an ordered delivery path with authentication results.
Local