What this checker looks at
We read three DNS records for each domain, live:
- DMARC, the TXT record at
_dmarc.yourdomain.com. It tells receivers what to do with mail that fails authentication: deliver it, send it to spam, or reject it. - SPF, the TXT record that starts with
v=spf1. It lists the servers allowed to send as you. SPF breaks past 10 DNS lookups, so we count them through every include. - MX, where mail for the domain goes, with the provider's name when the hostname makes it clear.
SPF and DKIM prove a message may use your domain, DMARC says what happens when they fail, and MX decides where replies go. Without MX, a customer who answers your password reset email gets a bounce. Our guide to replying from a custom domain covers that side.
If you're sending from several domains, it's normal for one to be set up right and another to have no DMARC at all, so paste them all and compare.
DKIM isn't checked here: it needs a selector from your sending provider, and if we guessed the selector wrong, a working key would look missing.
How to read your DMARC checker results
Each domain gets three pills: green is set up right, amber works but leaves something open, and red is missing or broken. Click a row or card for the raw record and a fix you can paste.
For DMARC, the p= policy matters most:
p=noneis monitoring only. Receivers send you reports but still deliver mail that fails, so it shows amber.p=quarantineasks receivers to treat failing mail as suspicious, usually the spam folder.p=rejectasks them to refuse it.
Quarantine or reject plus a rua= address is green. rua is where receivers send aggregate reports, which show whether your own senders pass before you enforce.
RFC 9989 replaced the original DMARC spec, RFC 7489, in May 2026, and changed a few tags:
pctis gone.pct=0becomest=y,pct=100can be deleted, and partial values likepct=50have no replacement.t=yis the new test mode: receivers handlerejectasquarantineandquarantineasnone.np, now part of the main spec, sets the policy for subdomains that don't exist.rfandriare historic, and receivers ignore them.
Policy lookup now walks up the DNS tree instead of using the Public Suffix List, so a subdomain without its own record shows its parent's as "inherited from".
The rules that made DMARC required
Since February 1, 2024, Gmail requires every sender to set up SPF or DKIM. If you send more than 5,000 messages a day to Gmail accounts, you need SPF, DKIM and DMARC, and your From domain has to align with SPF or DKIM. The DMARC policy can be none.
Yahoo asks the same minimum of everyone: SPF or DKIM. Bulk senders need both, plus a valid DMARC policy of at least p=none, and DMARC has to pass. Relaxed alignment is fine. Yahoo doesn't put a number on "bulk".
Microsoft followed on May 5, 2025, for Outlook.com: domains sending more than 5,000 emails a day must pass SPF and DKIM and publish DMARC at p=none or stricter, aligned with SPF or DKIM. Mail that doesn't comply goes to junk and may be rejected.
So p=none is the floor at all three. Our take: publish SPF, DKIM and DMARC on every domain you send from, whatever your volume. With transactional email across domains, each domain needs its own set.
Domains that don't send email
If you own several domains, some are probably parked. Without records, anyone can send mail that claims to come from them, and receivers have no policy telling them to refuse it.
Three records lock a parked domain down:
| Host | Type | Value |
|---|---|---|
yourdomain.com | TXT | v=spf1 -all |
_dmarc.yourdomain.com | TXT | v=DMARC1; p=reject; |
yourdomain.com | MX | 0 . |
v=spf1 -all says no server may send as the domain, p=reject tells receivers to refuse anything that tries, and the null MX (0 ., from RFC 7505) says it accepts no mail, so senders fail right away instead of retrying.
The checker suggests this set when a domain has no MX, SPF or DMARC. If you later want mail on one of them, our guide to email hosting for several domains compares the options.
Fixes for the common failures
No DMARC record
Add a TXT record with the host _dmarc and this value:
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
Use an address you actually read. After a week or two of reports where your real senders pass, move to p=quarantine, then p=reject.
Two SPF records
A domain can only have one SPF record. With two, SPF fails with a permanent error for every message. Merge them into one v=spf1 with every include and a single ~all or -all:
Before, two records:
v=spf1 include:_spf.google.com ~all
v=spf1 include:mailgun.org ~all
After, one record:
v=spf1 include:_spf.google.com include:mailgun.org ~all
Too many SPF lookups
RFC 7208 caps SPF at 10 DNS lookups, counted through nested includes, and at 2 lookups that come back empty. Past either limit, SPF fails. To get under, remove includes you no longer use, swap a and mx for the ip4 and ip6 addresses behind them, and drop ptr.
Some senders, like Postmark, use a Return-Path subdomain with its own SPF and don't need your root record at all. Mailyond works the same way: each domain you connect takes one 5-minute DNS setup of three records (DKIM, Return-Path and MX), and your root SPF record stays as it is. For a full SPF, DKIM and DMARC record set on registrar DNS, see our Namecheap guide.
FAQ
How do I check my DMARC record?
Paste your domain in the box at the top of this page and click Check domains. To check by hand, look up the TXT record at _dmarc.yourdomain.com, for example with dig TXT _dmarc.yourdomain.com. If nothing comes back, the domain has no DMARC record.
How do I check if my DMARC is working?
The record only tells you the policy. Whether your mail passes shows up in two places: the aggregate reports sent to your rua address, and the headers of a message you send, where the Authentication-Results line says dmarc=pass or dmarc=fail. Add rua and read about a week of reports before you move past p=none.
How do I create a simple DMARC record?
Add a TXT record with the host _dmarc and the value v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com, using an address you actually read. Most DNS panels add your domain to the host for you, so type only _dmarc. Then check the domain here again to confirm it's live.
Is p=none enough?
For the Gmail, Yahoo and Outlook.com bulk-sender rules, yes: all three accept p=none. It doesn't stop anyone from spoofing your domain, though, because mail that fails DMARC still gets delivered. Treat it as the monitoring step before quarantine or reject.
What happened to the pct tag?
RFC 9989, published in May 2026, removed it. If you used pct=0 to test, switch to t=y. If your record has pct=100, delete it, since 100 was the default anyway. A partial rollout like pct=50 has no replacement, so receivers that follow the new spec apply your policy to all failing mail.
Can I check multiple domains at once?
Yes, up to 10 per check, one per line or separated by commas or spaces. Each domain gets its own row, and you don't need an account.
Does a domain that never sends email need DMARC?
Yes. Without it, anyone can send mail that claims to come from that domain. Publish v=DMARC1; p=reject; at _dmarc, v=spf1 -all on the domain itself and a null MX (0 .), and it's locked down.
Do you store the domains I check?
No. Each check runs live against public DNS (Cloudflare's resolver, with Google's as a fallback) and the result goes straight back to your browser. We don't save the domains or log them, and our analytics only records how many you checked, never which ones. If you share a link to your results, the domains sit after the # in the URL, and browsers don't send that part to our server.