DMARC Record Builder
Free online DMARC record builder. Create Domain-based Message Authentication, Reporting & Conformance DNS TXT records with p, sp, rua, ruf, fo, adkim, aspf, ri, and pct tags. Supports none, quarantine, and reject policies, relaxed and strict alignment, and aggregate/forensic report destinations. Warns when enforcement is set without reporting. Generates the exact record to publish at _dmarc.yourdomain.com. No signup required.
Loading tool...
What is DMARC Record Builder?
A DMARC record builder helps you compose a valid Domain-based Message Authentication, Reporting & Conformance (DMARC) DNS TXT record. Defined in RFC 7489 and published at _dmarc.yourdomain.com, DMARC tells receiving mail servers what to do when SPF or DKIM alignment fails - monitor, quarantine, or reject - and where to send failure reports. This tool lets you set the policy (p), subdomain policy (sp), report destinations (rua, ruf), forensic options (fo), alignment modes (adkim, aspf), report interval (ri), and enforcement percentage (pct), and validates everything against the RFC.
Key Benefits
- Validates mailto: URIs for report destinations
- Warns when enforcement is set without reporting
- Relaxed and strict alignment for SPF and DKIM
- Percentage rollout for safe enforcement ramp-up
Common Use Cases
- β’Email authentication policy setup
- β’Phishing and spoofing prevention
- β’Compliance with Gmail and Yahoo bulk sender rules
- β’Auditing existing DMARC records
How to Build a DMARC Record
- Start with p=none: Begin in monitor-only mode (p=none) so you collect aggregate and forensic reports without rejecting mail.
- Add a rua destination: Set rua=mailto:[email protected] so receivers send daily aggregate reports of authentication results.
- Analyze reports and ramp up: Review rua reports for unauthorized senders, then move to p=quarantine and increase pct toward 100%.
- Enforce with p=reject: Once all legitimate mail passes SPF/DKIM alignment, set p=reject and keep monitoring rua for regressions.
Key Features
- Full tag support: p, sp, rua, ruf, fo, adkim, aspf, ri, pct, and rf per RFC 7489
- none, quarantine, and reject policies for both domain and subdomains
- mailto: URI validation for rua and ruf report destinations
- Warns when enforcement is set without an aggregate report address
- Relaxed and strict DKIM and SPF alignment modes
- One-click copy and download of the TXT record with length tracking