DMARC Check

Analyze DMARC policies for email protection and reporting configuration.

Examples
About DMARC

DMARC (Domain-based Message Authentication, Reporting & Conformance) protects your domain from email spoofing.

A DMARC policy of reject provides the strongest protection, while none only monitors without enforcing.

DMARC Check — Verify Email Spoofing Protection

A DMARC check queries the _dmarc subdomain of any domain to retrieve the DMARC TXT record, revealing the policy (none/quarantine/reject), reporting addresses, and alignment settings.

DMARC prevents email spoofing by telling receiving servers what to do when an email fails SPF or DKIM authentication. Our checker queries _dmarc.yourdomain.com directly and returns the full record with parsed fields: p= policy, sp= subdomain policy, pct= percentage, rua= aggregate reports, ruf= forensic reports, and adkim/aspf alignment modes.

What is DMARC and Why Does It Matter?

DMARC is an email authentication standard that uses SPF and DKIM results to enforce a policy: monitor (none), quarantine (spam folder), or reject unauthorized senders attempting to spoof your domain.

Without DMARC, anyone can send email claiming to be from your domain. A DMARC policy of 'reject' instructs receiving servers to block unauthenticated email entirely. 'Quarantine' sends suspicious email to spam. 'None' only monitors and generates reports — recommended as a first step before enforcing.

DMARC Policies: none vs quarantine vs reject

p=none monitors only. p=quarantine marks unauthorized email as spam. p=reject blocks it completely. Start with p=none, collect reports, then progressively enforce for maximum protection.

Most organizations start with p=none to collect DMARC reports and identify legitimate senders before enforcing. Once all authorized senders pass SPF/DKIM, upgrade to p=quarantine. After verifying no legitimate email is being filtered, move to p=reject. The pct= tag lets you apply the policy to a percentage of messages for gradual rollout.

SPF + DKIM + DMARC: The Email Authentication Triplet

SPF authorizes sending IPs, DKIM signs message content, and DMARC ties them together with a policy and reporting mechanism. All three together provide comprehensive email spoofing protection.

DMARC requires at least one of SPF or DKIM to align with the From domain to pass. SPF alone is bypassed through email forwarding. DKIM alone doesn't prevent spoofing of the display address. Together under DMARC enforcement, domain impersonation becomes technically infeasible for most attackers.

Check DMARC policy, verify SPF/DKIM alignment, and protect your domain from email spoofing.

Check DMARC now

Use Cases

Security teams audit DMARC posture across all managed domains. Email deliverability consultants diagnose why legitimate email is being rejected. Compliance teams verify DMARC enforcement before certification audits. Brand protection teams monitor DMARC reports to detect phishing campaigns spoofing their domains.