DMARC Record Generator

DMARC Record Generator

Configure policy and reporting to create one deployable TXT record.

Domain policy

Subdomain policy

Authentication alignment

DKIM alignment

SPF alignment

TXT hostname

_dmarc

TXT record value

v=DMARC1; p=none; rua=mailto:
  • Enter a valid domain.
  • rua must be a valid email address.

Email policy generator

What is a DMARC record?

DMARC uses aligned SPF or DKIM results to tell receivers how to handle authentication failures. It can also send aggregate or forensic reports to the domain owner.

The generator converts policy controls into one _dmarc TXT value. It does not query or modify DNS, and inputs stay in the browser.

Configurable fields

P

Domain and subdomain policy

Choose none, quarantine or reject and optionally set sp.

RUA

Report destinations

Configure aggregate rua, optional ruf and report interval.

ALIGN

Authentication alignment

Set relaxed or strict SPF and DKIM alignment.

Why use a DMARC generator?

A misplaced separator, invalid report URI, wrong percentage or duplicate record can weaken enforcement and stop reports from arriving.

Avoid syntax errors

Generate tags in a predictable order and validate addresses and ranges.

Support staged rollout

Start with p=none reports, then increase coverage and policy strength.

Keep one policy record

Produce one complete value instead of publishing conflicting DMARC records.

How should the generated DMARC be deployed?

Confirm every legitimate sender aligns through SPF or DKIM before moving to enforcement.

  1. 01

    Enter domain and report email

    The generator produces the _dmarc hostname and mailto URI.

  2. 02

    Choose policy strength

    Set p, sp and pct for the current authentication maturity.

  3. 03

    Publish one TXT value

    Add it at the DNS provider without a second DMARC record.

  4. 04

    Review reports and enforce

    Identify legitimate sources before moving toward quarantine or reject.

DMARC generator FAQ

What hostname should be used for DMARC?

Use _dmarc, or the full _dmarc.example.com when the DNS provider requires it. Do not publish DMARC at the zone root.

Should a new domain start with p=reject?

Only when every legitimate sender is known to align. Most deployments should collect rua reports with p=none first.

What is the difference between rua and ruf?

rua receives aggregate XML reports. ruf requests forensic failure reports, has lower provider support and may have privacy implications.

Can a domain publish multiple DMARC records?

No. The _dmarc hostname must have one valid DMARC policy. Multiple records make evaluation fail.

Will the generator change DNS?

No. It creates text locally in the browser. You publish it through your DNS provider.