DMARC Record Checker

Enter a domain to fetch its live DMARC record and validate it against RFC 9989 — the current standard that replaced RFC 7489. You get the effective policy, subdomain and alignment behavior, report destinations, and prioritized fixes.

Check a domain's DMARC record

Enter a domain to look up its published DMARC policy, reporting addresses, and alignment settings.

We query the public DNS TXT record at _dmarc.<domain> and, when it is missing, the organizational domain — exactly as receivers do under RFC 9989.

We query public DNS for _dmarc records and report-authorization records on your behalf. The domain you enter is used only to run the lookup; check results are not stored.

How the DMARC Record Checker works

We run the RFC 9989 policy discovery

First _dmarc.yourdomain.com is queried. If it has no DMARC record, the checker performs the bounded tree walk to your organizational domain — the same discovery receivers perform.

The record is parsed against the current standard

Every current tag (p, sp, np, t, psd, adkim, aspf, rua, ruf, fo) is validated, defaults are applied, and removed tags like pct are flagged as legacy instead of being honored.

Reporting paths are verified

Each rua/ruf destination is checked for a valid mailto URI. Destinations outside your organizational domain are tested for the external authorization record receivers require.

You get an honest verdict and fixes

The result distinguishes a missing record, an invalid record, an inherited policy, and monitoring versus enforcing policies — with findings ordered by severity. Unknown answers are never counted as passes.

What this tool does and does not tell you

  • A published DMARC policy is enforced by receivers at delivery time; this checker reads DNS and cannot prove what a specific mailbox provider did with a specific message.
  • DMARC alignment depends on SPF and DKIM. A valid DMARC record with broken SPF or DKIM still fails — check those layers too.
  • A DNS timeout or server failure is shown as unknown, never as a pass or a clean bill of health.
  • Report receivers can ignore rua/ruf requests even when everything is authorized, and many no longer send failure (ruf) reports for privacy reasons.
  • A passing DMARC configuration is not a guarantee of inbox placement; reputation and content still decide where mail lands.

Related free tools

DMARC Record Generator

Build a correct RFC 9989 DMARC record with reporting addresses, then publish it as one TXT record.

Open tool

SPF Record Checker

Verify the SPF record your DMARC alignment depends on, including nested includes and the 10-lookup limit.

Open tool

DKIM Record Checker

Inspect the DKIM public key for a selector and confirm the signature side of DMARC alignment.

Open tool

BIMI Record Checker

Check the BIMI record that displays your logo in supporting inboxes once DMARC enforcement is in place.

Open tool

Frequently Asked Questions

What is a DMARC record?

A DMARC record is a single TXT record published at _dmarc.yourdomain.com that tells receiving mail servers how to handle messages that fail SPF and DKIM alignment for your domain, and where to send reports about that mail. It is defined by RFC 9989, which replaced the older RFC 7489.

Why does the checker look at my organizational domain too?

RFC 9989 defines a bounded tree walk: when a subdomain has no _dmarc record of its own, receivers inherit the policy published at the organizational domain. This checker follows the same rule, so a result marked "inherited" is exactly what receivers will apply.

Is p=none enough to protect my domain?

No. p=none is a monitoring policy: receivers report failures but deliver the mail anyway, so spoofed messages still reach inboxes. It is the right first step while you discover legitimate senders, but protection only starts at p=quarantine or p=reject.

What happened to the pct tag?

RFC 9989 removed pct (along with ri and rf). Enforcement now applies to all failing mail; partial rollouts are expressed by moving between none, quarantine and reject instead. If your record still contains pct, it is ignored by current receivers and can be deleted.

Why am I not receiving DMARC reports at an outside address?

When a report address lives in a different organizational domain, that domain must explicitly opt in by publishing v=DMARC1 at <your-domain>._report._dmarc.<their-domain>. Without that authorization record, receivers drop the reports. This checker verifies the authorization for every external destination in your record.

Does a valid DMARC record guarantee inbox placement?

No. DMARC stops exact-domain spoofing and proves your authentication posture, but inbox placement also depends on sender reputation, engagement, and content. Treat DMARC as required hygiene, not a deliverability guarantee.

Increase Your Sales Right Now

Automate Sales Outreach & Get Booked!

Start Free Trial

(14 Day Free Trial, No CC Required)