DMARC Record Generator
🔒 In your browserBuild a DMARC record with the right policy, reporting and alignment.
How it works
Build a DMARC record — the policy that tells receivers what to do with mail claiming to be from you that fails SPF and DKIM, and where to send reports. Publish it as a TXT record at _dmarc.yourdomain.com.
v=DMARC1; p=none
Where to publish
Host: _dmarc · Type: TXT · Value: the record above
Starting at p=none is right — collect reports for a few weeks, confirm your legitimate mail passes, then move to quarantine and finally reject.
🔒 Runs in your browser: records, keys and headers are processed locally and never uploaded — including DKIM private keys, which never leave this device.
About the DMARC Record Generator
This free DMARC record generator builds the TXT record that protects your domain from spoofing. Choose your enforcement policy, where reports should be sent, how much of your mail the policy covers, and the alignment mode — then publish the result at _dmarc.yourdomain.com.
It runs entirely in your browser, with guidance on the safe rollout order.
How to publish it
- Create a TXT record with the host _dmarc (so it resolves at _dmarc.yourdomain.com).
- Paste the generated record as the value.
- Start at p=none with an rua address and read the reports before enforcing.
A safe rollout
Publish p=none with reporting, and leave it for a few weeks. Use the reports to find every legitimate sender — there are usually more than you expect, like invoicing tools and CRMs — and get each one passing SPF or DKIM. Then move to quarantine, and finally reject. Rushing to reject blocks your own mail silently.
Frequently asked questions
Where does the DMARC record go?
As a TXT record on the host _dmarc, so it resolves at _dmarc.yourdomain.com. Not at your domain root.
What should I set rua to?
Any mailbox you'll actually read, for example dmarc@yourdomain.com. Reports arrive as XML, which you can read with our DMARC Report Viewer.
What does pct do?
It applies your policy to only a percentage of failing mail, which lets you roll enforcement out gradually. Leave it at 100 unless you're phasing in a stricter policy.
Relaxed or strict alignment?
Relaxed is right for almost everyone — it allows subdomains to align with your organisational domain. Strict requires an exact domain match and breaks many legitimate setups.