DMARC Record Generator

Create a correct DMARC record for your domain without memorizing RFC 9989 syntax. Pick a policy, add report addresses, and copy a ready-to-publish TXT record.

Build your DMARC record

Answer a few questions about your domain and reporting, and get a ready-to-publish TXT record that follows the current DMARC specification (RFC 9989).

The domain you send email from, e.g. example.com. The record is published at _dmarc.yourdomain.

Policy for your domain (p)

What receivers should do with mail that fails DMARC. Start with monitor; p=none does not stop spoofed mail from being delivered.

Applies to subdomains such as mail.example.com.

Policy for subdomains that do not exist in DNS (new in RFC 9989).

Aggregate report addresses (rua)

Mailboxes that receive daily XML reports about who sends mail as your domain. Strongly recommended — without them you are blind to failures and spoofing attempts.

Failure report addresses (ruf, optional)

Mailboxes that receive a report for individual failing messages. These reports can contain real message metadata and sometimes content — use a mailbox you control, and note that many receivers never send them.

Advanced: public suffix flag (psd)

psd tells receivers whether this domain is itself a public suffix — an entry on the Public Suffix List such as co.uk or com.au. Setting psd=y for an ordinary domain makes the record wrong and changes how subdomains are treated. Almost every domain should leave this unset.

Everything runs in your browser. The domain and report addresses you enter are never sent to a server or stored.

How the DMARC Record Generator works

Enter your domain

The domain you send email from. It sets the DNS host (_dmarc.yourdomain) and is used to detect report addresses that live outside your domain.

Choose a policy

Decide what receivers do with failing mail: monitor with p=none first, then quarantine or reject once your reports are clean. Optionally set different policies for subdomains and non-existent subdomains.

Add report addresses

List mailboxes for aggregate reports so you can see every sender using your domain. Failure reports are optional and come with privacy trade-offs the tool explains.

Generate and review

The record is built deterministically in canonical order and checked against the same RFC 9989 parser our checker tool uses, with plain-language notes for every tag.

Publish one TXT record

Add the value to your DNS provider at the host shown. If a DMARC record already exists, replace it — a domain must publish exactly one.

Roll out gradually

Read reports for a couple of weeks, fix failing legitimate senders, then move from p=none to quarantine and reject. Verify the published record with our DMARC Record Checker.

What this tool does and does not tell you

  • The generator builds the record but publishes nothing; you must add it to your DNS provider yourself.
  • p=none is monitoring only — it never stops spoofed mail from being delivered. Enforcement requires quarantine or reject.
  • A DMARC record does not guarantee inbox placement. It depends on correctly configured SPF and DKIM, and receivers still weigh reputation, engagement, and content.
  • Report delivery is voluntary: receivers may ignore report requests, and destinations outside your domain must publish an authorization record first.
  • This tool follows RFC 9989 (May 2026). The removed pct, ri and rf tags are never generated, and there is no percentage-based rollout in the current specification.
  • The record is validated for syntax and semantics, but only a live check of your published DNS can confirm what receivers actually see.

Related free tools

DMARC Record Checker

Look up a live domain and validate its published DMARC record, policy inheritance, and report authorization against RFC 9989.

Open tool

SPF Record Generator

Build the SPF record that lists which servers may send mail as your domain — DMARC builds on it.

Open tool

DKIM Record Generator

Create a DKIM key pair and DNS record so your outgoing mail carries a cryptographic signature.

Open tool

BIMI Record Generator

Once DMARC is enforced, publish a BIMI record to make your logo eligible for display in supporting inboxes.

Open tool

Frequently Asked Questions

What is a DMARC record?

A DMARC record is a single TXT record published at _dmarc.yourdomain in DNS. It tells receiving mail servers what to do with messages that fail SPF and DKIM alignment checks, and where to send reports about mail claiming to be from your domain.

Which policy should I start with?

Start with p=none plus an aggregate report (rua) address. This monitors mail without affecting delivery, so you can see every sender using your domain. Once reports show all legitimate mail passes SPF or DKIM alignment, move to p=quarantine and then p=reject. Never assume p=none blocks spoofed mail — it only watches.

Why is there no pct (percentage) option?

The pct tag was removed by RFC 9989, the current DMARC specification published in May 2026, so this generator deliberately does not offer it. Enforcement now applies to all mail; the safe rollout path is p=none monitoring followed by full quarantine or reject, not a percentage of messages.

What are aggregate (rua) and failure (ruf) reports?

Aggregate reports are daily XML summaries from receivers showing which servers sent mail as your domain and whether it passed. Failure reports are per-message forensic reports; they can contain message metadata and sometimes content, so point them at a mailbox you control and expect some receivers to never send them.

Can I send DMARC reports to an address at another company?

Yes, but the destination domain must authorize it by publishing a TXT record named yourdomain._report._dmarc.their-domain with the value v=DMARC1. The generator shows the exact authorization record when you use an external address. Even then, the destination operator decides whether to accept and send reports for you.

Does a DMARC record guarantee inbox placement?

No. DMARC tells receivers how to handle mail that fails authentication; it protects your domain from direct spoofing and gives you visibility through reports. Inbox placement still depends on SPF and DKIM being correctly configured, sender reputation, engagement, and content.

Increase Your Sales Right Now

Automate Sales Outreach & Get Booked!

Start Free Trial

(14 Day Free Trial, No CC Required)