NEW CASE
Antana

We create digital solutions that work for businesses


Give us a call +38 (066) 35-14-529

Let's take the first step towards your website — write to us

Close
Tools

DMARC Check

The domain DMARC policy: p, rua, ruf.

What DMARC is for

SPF and DKIM check the message but do not tell the receiver what to do when it fails. DMARC is that instruction.

You decide what happens to fakes Without DMARC the receiver decides for itself. With it you say plainly: send these to spam, or reject them outright.
Reports on spoofing attempts Summaries arrive at the address you specify: who sent mail as you, and from where. Often this is how the problem is discovered.
A requirement of major providers Since 2024 Gmail and Yahoo require DMARC from bulk senders. Without it the campaign simply will not arrive.
Brand protection A scam sent in your company’s name damages your reputation even when your server had nothing to do with it.

Policies from soft to strict

Move up gradually, checking the reports at each stage.

p=none Block nothing, just send reports. Always start here: a month of observation reveals which services send as you.
p=quarantine Suspicious mail goes to spam. The middle step, once you trust the setup but are not ready to reject.
p=reject Reject at the door. The strongest protection, but a misconfiguration means mail vanishes without trace.
rua= The address for reports. Without it DMARC runs blind — you learn about neither spoofing nor your own mistakes.

Getting to a strict policy safely

1 Start with p=none The record does not affect delivery but reports start arriving. Be sure to set an address in rua.
2 Read reports for a month You will find services you forgot: an old CRM, a website form, accounting software. Each needs adding to SPF.
3 Switch to quarantine Once the reports show only legitimate senders, you can start sending suspicious mail to spam.
4 Move to reject The final step after a few more weeks of monitoring. Spoofing your domain is now practically impossible.

Check a domain DMARC record

The tool looks up the TXT record on the _dmarc subdomain of your domain and shows the active DMARC policy: level (none / quarantine / reject), rua/ruf report addresses, application percentage and alignment modes. DMARC is the "lock" on top of SPF and DKIM that tells mail systems what to do with forged emails.

Without DMARC your domain is open to phishing in your name, and since 2024 Gmail and Outlook require DMARC for bulk senders. If there is no record or it is p=none with no hardening plan — start with monitoring and gradually move to quarantine and reject. Generate a correct record with our DMARC generator.

FAQ

What is DMARC?
DMARC is a DNS policy telling mail systems how to handle emails that fail SPF or DKIM: allow, spam or reject.
What do p=none, quarantine, reject mean?
p=none only collects reports, p=quarantine sends suspicious mail to spam, p=reject rejects it entirely. Start with none, then tighten.
What is rua?
rua is the address where reports about your mail checks are sent. They show who tries to send emails as you.
Does DMARC work without SPF?
No. DMARC relies on SPF and DKIM. Set them up first, then add the DMARC policy.
Telegram Viber Call us