Free Online Tool

DMARC Lookup

Check any domain's DMARC record — view policy, alignment settings, reporting URIs, and email security strength.

Features · Advantages · Benefits

Why check your DMARC record?

DMARC protects your domain from email spoofing. Without it, anyone can send email pretending to be you.

Feature

Full Record Parsing

Retrieves and parses every DMARC tag — policy, subdomain policy, alignment modes, reporting URIs, and failure options.

Advantage

Strength Assessment

Instantly see whether your DMARC configuration is strong, moderate, or weak based on policy and enforcement percentage.

Benefit

Stop Domain Spoofing

Know exactly how protected your domain is against phishing and spoofing attacks before they reach your customers.

p=reject

The strongest policy. Emails failing DMARC are rejected outright by receiving mail servers.

p=quarantine

Failing emails go to spam. Better than nothing, but enforcement is partial.

p=none

Monitor-only mode. No action is taken — useful during initial rollout to collect reports.

rua / ruf

Aggregate and forensic report URIs. Where receiving servers send DMARC reports for analysis.

Looking up DMARC record…

DMARC Record for

FAQ

Frequently asked questions

Everything you need to know about DMARC records and email security.

DMARC (Domain-based Message Authentication, Reporting & Conformance) is a DNS TXT record published at _dmarc.yourdomain.com. It tells receiving mail servers what to do with emails that fail SPF or DKIM checks, and where to send reports.
p=none monitors only — no action is taken on failing emails. p=quarantine sends failing emails to spam. p=reject blocks failing emails entirely. Most domains should aim for p=reject at 100% enforcement.
Without DMARC, anyone can forge your domain in the "From" address of an email. This enables phishing attacks that impersonate your brand. DMARC, combined with SPF and DKIM, makes spoofing your domain significantly harder.
rua (Reporting URI for Aggregate reports) receives daily summary XML reports of all emails claiming to be from your domain. ruf (Reporting URI for Forensic reports) receives copies of individual failing messages. rua is strongly recommended; ruf is optional.
pct controls what percentage of failing emails are subject to the DMARC policy. pct=100 (the default) applies the policy to all failing messages. Lower values allow gradual rollout — e.g. pct=10 applies the policy to only 10% of failures.
Alignment means the domain in the From header must match the domain used in SPF or DKIM. Relaxed alignment (r) allows subdomains to pass. Strict alignment (s) requires an exact match. Strict is more secure but can break some email forwarding setups.

Need more domain checks?

Combine DMARC with DNS, WHOIS, and SEO data in one free report.

Run Free Complete Analysis