Domain and subdomain policy
Choose none, quarantine or reject and optionally set sp.
Configure policy and reporting to create one deployable TXT record.
Domain policy
Subdomain policy
Authentication alignment
DKIM alignment
SPF alignment
TXT hostname
_dmarcTXT record value
v=DMARC1; p=none; rua=mailto:Email policy generator
DMARC uses aligned SPF or DKIM results to tell receivers how to handle authentication failures. It can also send aggregate or forensic reports to the domain owner.
The generator converts policy controls into one _dmarc TXT value. It does not query or modify DNS, and inputs stay in the browser.
Choose none, quarantine or reject and optionally set sp.
Configure aggregate rua, optional ruf and report interval.
Set relaxed or strict SPF and DKIM alignment.
A misplaced separator, invalid report URI, wrong percentage or duplicate record can weaken enforcement and stop reports from arriving.
Generate tags in a predictable order and validate addresses and ranges.
Start with p=none reports, then increase coverage and policy strength.
Produce one complete value instead of publishing conflicting DMARC records.
Confirm every legitimate sender aligns through SPF or DKIM before moving to enforcement.
The generator produces the _dmarc hostname and mailto URI.
Set p, sp and pct for the current authentication maturity.
Add it at the DNS provider without a second DMARC record.
Identify legitimate sources before moving toward quarantine or reject.
Use _dmarc, or the full _dmarc.example.com when the DNS provider requires it. Do not publish DMARC at the zone root.
Only when every legitimate sender is known to align. Most deployments should collect rua reports with p=none first.
rua receives aggregate XML reports. ruf requests forensic failure reports, has lower provider support and may have privacy implications.
No. The _dmarc hostname must have one valid DMARC policy. Multiple records make evaluation fail.
No. It creates text locally in the browser. You publish it through your DNS provider.
After publishing, use the checker to verify the actual DNS response.