[{"data":1,"prerenderedAt":1037},["ShallowReactive",2],{"dmarc-checker":3,"mdc--awunol-key":69,"mdc-h43l8l-key":167,"mdc-vjkncv-key":379,"mdc--yqmmqg-key":461,"mdc-uimhfj-key":628,"mdc-5pmwsy-key":652,"mdc-i4i9bx-key":697,"mdc--x7ka0t-key":729,"mdc--ijn201-key":757,"mdc-q32tp9-key":794,"mdc--atoi91-key":802,"mdc--6pbp86-key":838,"mdc--3olt5m-key":855},{"id":4,"title":5,"body":6,"cta":7,"description":6,"extension":12,"faq":13,"hero":40,"lastUpdated":44,"meta":45,"navigation":46,"path":47,"sections":48,"seo":64,"stem":67,"__hash__":68},"dmarcChecker\u002Ftools\u002Fdmarc-checker.yml","Dmarc Checker",null,{"title":8,"description":9,"label":10,"to":11},"Sending your app's email from these domains?","Mailyond sends it and receives the replies on the same domain, with three DNS records per domain. $10\u002Fmonth for up to 5 domains, $40 for up to 30.","Try it free for 7 days","\u002Fsignup","yml",{"title":14,"items":15},"FAQ",[16,19,22,25,28,31,34,37],{"title":17,"description":18},"How do I check my DMARC record?","Paste your domain in the box at the top of this page and click Check domains. To check by hand, look up the TXT record at `_dmarc.yourdomain.com`, for example with `dig TXT _dmarc.yourdomain.com`. If nothing comes back, the domain has no DMARC record.",{"title":20,"description":21},"How do I check if my DMARC is working?","The record only tells you the policy. Whether your mail passes shows up in two places: the aggregate reports sent to your `rua` address, and the headers of a message you send, where the Authentication-Results line says `dmarc=pass` or `dmarc=fail`. Add `rua` and read about a week of reports before you move past `p=none`.",{"title":23,"description":24},"How do I create a simple DMARC record?","Add a TXT record with the host `_dmarc` and the value `v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com`, using an address you actually read. Most DNS panels add your domain to the host for you, so type only `_dmarc`. Then check the domain here again to confirm it's live.",{"title":26,"description":27},"Is p=none enough?","For the Gmail, Yahoo and Outlook.com bulk-sender rules, yes: all three accept `p=none`. It doesn't stop anyone from spoofing your domain, though, because mail that fails DMARC still gets delivered. Treat it as the monitoring step before `quarantine` or `reject`.",{"title":29,"description":30},"What happened to the pct tag?","RFC 9989, published in May 2026, removed it. If you used `pct=0` to test, switch to `t=y`. If your record has `pct=100`, delete it, since 100 was the default anyway. A partial rollout like `pct=50` has no replacement, so receivers that follow the new spec apply your policy to all failing mail.",{"title":32,"description":33},"Can I check multiple domains at once?","Yes, up to 10 per check, one per line or separated by commas or spaces. Each domain gets its own row, and you don't need an account.",{"title":35,"description":36},"Does a domain that never sends email need DMARC?","Yes. Without it, anyone can send mail that claims to come from that domain. Publish `v=DMARC1; p=reject;` at `_dmarc`, `v=spf1 -all` on the domain itself and a null MX (`0 .`), and it's locked down.",{"title":38,"description":39},"Do you store the domains I check?","No. Each check runs live against public DNS (Cloudflare's resolver, with Google's as a fallback) and the result goes straight back to your browser. We don't save the domains or log them, and our analytics only records how many you checked, never which ones. If you share a link to your results, the domains sit after the `#` in the URL, and browsers don't send that part to our server.",{"title":41,"description":42,"note":43},"DMARC checker for all your domains","This free DMARC checker reads the DMARC, SPF and MX records for up to 10 domains at once and tells you what to fix, in plain English.","No signup, and nothing is stored.","2026-10-11",{},true,"\u002Ftools\u002Fdmarc-checker",[49,52,55,58,61],{"title":50,"content":51},"What this checker looks at","We read three DNS records for each domain, live:\n\n- **DMARC**, the TXT record at `_dmarc.yourdomain.com`. It tells receivers what to do with mail that fails authentication: deliver it, send it to spam, or reject it.\n- **SPF**, the TXT record that starts with `v=spf1`. It lists the servers allowed to send as you. SPF breaks past 10 DNS lookups, so we count them through every include.\n- **MX**, where mail for the domain goes, with the provider's name when the hostname makes it clear.\n\nSPF and DKIM prove a message may use your domain, DMARC says what happens when they fail, and MX decides where replies go. Without MX, a customer who answers your password reset email gets a bounce. Our guide to [replying from a custom domain](\u002Fblog\u002Freply-to-email-from-custom-domain) covers that side.\n\nIf you're [sending from several domains](\u002Fblog\u002Fsend-email-from-multiple-domains), it's normal for one to be set up right and another to have no DMARC at all, so paste them all and compare.\n\nDKIM isn't checked here: it needs a selector from your sending provider, and if we guessed the selector wrong, a working key would look missing.\n",{"title":53,"content":54},"How to read your DMARC checker results","Each domain gets three pills: green is set up right, amber works but leaves something open, and red is missing or broken. Click a row or card for the raw record and a fix you can paste.\n\nFor DMARC, the `p=` policy matters most:\n\n- `p=none` is monitoring only. Receivers send you reports but still deliver mail that fails, so it shows amber.\n- `p=quarantine` asks receivers to treat failing mail as suspicious, usually the spam folder.\n- `p=reject` asks them to refuse it.\n\nQuarantine or reject plus a `rua=` address is green. `rua` is where receivers send aggregate reports, which show whether your own senders pass before you enforce.\n\n[RFC 9989](https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc9989) replaced the original DMARC spec, RFC 7489, in May 2026, and changed a few tags:\n\n- `pct` is gone. `pct=0` becomes `t=y`, `pct=100` can be deleted, and partial values like `pct=50` have no replacement.\n- `t=y` is the new test mode: receivers handle `reject` as `quarantine` and `quarantine` as `none`.\n- `np`, now part of the main spec, sets the policy for subdomains that don't exist.\n- `rf` and `ri` are historic, and receivers ignore them.\n\nPolicy lookup now walks up the DNS tree instead of using the Public Suffix List, so a subdomain without its own record shows its parent's as \"inherited from\".\n",{"title":56,"content":57},"The rules that made DMARC required","Since February 1, 2024, [Gmail](https:\u002F\u002Fsupport.google.com\u002Fa\u002Fanswer\u002F81126) requires every sender to set up SPF or DKIM. If you send more than 5,000 messages a day to Gmail accounts, you need SPF, DKIM and DMARC, and your From domain has to align with SPF or DKIM. The DMARC policy can be `none`.\n\n[Yahoo](https:\u002F\u002Fsenders.yahooinc.com\u002Fbest-practices\u002F) asks the same minimum of everyone: SPF or DKIM. Bulk senders need both, plus a valid DMARC policy of at least `p=none`, and DMARC has to pass. Relaxed alignment is fine. Yahoo doesn't put a number on \"bulk\".\n\n[Microsoft](https:\u002F\u002Fpostmaster.outlook.com\u002Fpolicies.aspx) followed on May 5, 2025, for Outlook.com: domains sending more than 5,000 emails a day must pass SPF and DKIM and publish DMARC at `p=none` or stricter, aligned with SPF or DKIM. Mail that doesn't comply goes to junk and may be rejected.\n\nSo `p=none` is the floor at all three. Our take: publish SPF, DKIM and DMARC on every domain you send from, whatever your volume. With [transactional email across domains](\u002Fblog\u002Ftransactional-email-for-multiple-domains), each domain needs its own set.\n",{"title":59,"content":60},"Domains that don't send email","If you own several domains, some are probably parked. Without records, anyone can send mail that claims to come from them, and receivers have no policy telling them to refuse it.\n\nThree records lock a parked domain down:\n\n| Host | Type | Value |\n| --- | --- | --- |\n| `yourdomain.com` | TXT | `v=spf1 -all` |\n| `_dmarc.yourdomain.com` | TXT | `v=DMARC1; p=reject;` |\n| `yourdomain.com` | MX | `0 .` |\n\n`v=spf1 -all` says no server may send as the domain, `p=reject` tells receivers to refuse anything that tries, and the null MX (`0 .`, from [RFC 7505](https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc7505)) says it accepts no mail, so senders fail right away instead of retrying.\n\nThe checker suggests this set when a domain has no MX, SPF or DMARC. If you later want mail on one of them, our guide to [email hosting for several domains](\u002Fblog\u002Femail-hosting-for-multiple-domains) compares the options.\n",{"title":62,"content":63},"Fixes for the common failures","### No DMARC record\n\nAdd a TXT record with the host `_dmarc` and this value:\n\n```txt\nv=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com\n```\n\nUse an address you actually read. After a week or two of reports where your real senders pass, move to `p=quarantine`, then `p=reject`.\n\n### Two SPF records\n\nA domain can only have one SPF record. With two, SPF fails with a permanent error for every message. Merge them into one `v=spf1` with every `include` and a single `~all` or `-all`:\n\n```txt\nBefore, two records:\nv=spf1 include:_spf.google.com ~all\nv=spf1 include:mailgun.org ~all\n\nAfter, one record:\nv=spf1 include:_spf.google.com include:mailgun.org ~all\n```\n\n### Too many SPF lookups\n\n[RFC 7208](https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc7208) caps SPF at 10 DNS lookups, counted through nested includes, and at 2 lookups that come back empty. Past either limit, SPF fails. To get under, remove includes you no longer use, swap `a` and `mx` for the `ip4` and `ip6` addresses behind them, and drop `ptr`.\n\nSome senders, like Postmark, use a Return-Path subdomain with its own SPF and don't need your root record at all. Mailyond works the same way: each domain you connect takes [one 5-minute DNS setup](\u002F#how-it-works) of three records (DKIM, Return-Path and MX), and your root SPF record stays as it is. For [a full SPF, DKIM and DMARC record set on registrar DNS](\u002Fblog\u002Fnamecheap-email-setup), see our Namecheap guide.\n",{"title":65,"description":66},"DMARC Checker: Check DMARC, SPF and MX for All Your Domains","Free DMARC checker. Paste up to 10 domains and see each one's DMARC policy, SPF record and MX in one table. No signup, and nothing is stored.","tools\u002Fdmarc-checker","w12zRSJx9MKfrsGDYm51MUZVr_-wWH3_R3PBBi8YVZc",{"data":70,"body":71},{},{"type":72,"children":73},"root",[74,82,135,149,162],{"type":75,"tag":76,"props":77,"children":78},"element","p",{},[79],{"type":80,"value":81},"text","We read three DNS records for each domain, live:",{"type":75,"tag":83,"props":84,"children":85},"ul",{},[86,107,125],{"type":75,"tag":87,"props":88,"children":89},"li",{},[90,96,98,105],{"type":75,"tag":91,"props":92,"children":93},"strong",{},[94],{"type":80,"value":95},"DMARC",{"type":80,"value":97},", the TXT record at ",{"type":75,"tag":99,"props":100,"children":102},"code",{"className":101},[],[103],{"type":80,"value":104},"_dmarc.yourdomain.com",{"type":80,"value":106},". It tells receivers what to do with mail that fails authentication: deliver it, send it to spam, or reject it.",{"type":75,"tag":87,"props":108,"children":109},{},[110,115,117,123],{"type":75,"tag":91,"props":111,"children":112},{},[113],{"type":80,"value":114},"SPF",{"type":80,"value":116},", the TXT record that starts with ",{"type":75,"tag":99,"props":118,"children":120},{"className":119},[],[121],{"type":80,"value":122},"v=spf1",{"type":80,"value":124},". It lists the servers allowed to send as you. SPF breaks past 10 DNS lookups, so we count them through every include.",{"type":75,"tag":87,"props":126,"children":127},{},[128,133],{"type":75,"tag":91,"props":129,"children":130},{},[131],{"type":80,"value":132},"MX",{"type":80,"value":134},", where mail for the domain goes, with the provider's name when the hostname makes it clear.",{"type":75,"tag":76,"props":136,"children":137},{},[138,140,147],{"type":80,"value":139},"SPF and DKIM prove a message may use your domain, DMARC says what happens when they fail, and MX decides where replies go. Without MX, a customer who answers your password reset email gets a bounce. Our guide to ",{"type":75,"tag":141,"props":142,"children":144},"a",{"href":143},"\u002Fblog\u002Freply-to-email-from-custom-domain",[145],{"type":80,"value":146},"replying from a custom domain",{"type":80,"value":148}," covers that side.",{"type":75,"tag":76,"props":150,"children":151},{},[152,154,160],{"type":80,"value":153},"If you're ",{"type":75,"tag":141,"props":155,"children":157},{"href":156},"\u002Fblog\u002Fsend-email-from-multiple-domains",[158],{"type":80,"value":159},"sending from several domains",{"type":80,"value":161},", it's normal for one to be set up right and another to have no DMARC at all, so paste them all and compare.",{"type":75,"tag":76,"props":163,"children":164},{},[165],{"type":80,"value":166},"DKIM isn't checked here: it needs a selector from your sending provider, and if we guessed the selector wrong, a working key would look missing.",{"data":168,"body":169},{},{"type":72,"children":170},[171,176,189,225,246,259,374],{"type":75,"tag":76,"props":172,"children":173},{},[174],{"type":80,"value":175},"Each domain gets three pills: green is set up right, amber works but leaves something open, and red is missing or broken. Click a row or card for the raw record and a fix you can paste.",{"type":75,"tag":76,"props":177,"children":178},{},[179,181,187],{"type":80,"value":180},"For DMARC, the ",{"type":75,"tag":99,"props":182,"children":184},{"className":183},[],[185],{"type":80,"value":186},"p=",{"type":80,"value":188}," policy matters most:",{"type":75,"tag":83,"props":190,"children":191},{},[192,203,214],{"type":75,"tag":87,"props":193,"children":194},{},[195,201],{"type":75,"tag":99,"props":196,"children":198},{"className":197},[],[199],{"type":80,"value":200},"p=none",{"type":80,"value":202}," is monitoring only. Receivers send you reports but still deliver mail that fails, so it shows amber.",{"type":75,"tag":87,"props":204,"children":205},{},[206,212],{"type":75,"tag":99,"props":207,"children":209},{"className":208},[],[210],{"type":80,"value":211},"p=quarantine",{"type":80,"value":213}," asks receivers to treat failing mail as suspicious, usually the spam folder.",{"type":75,"tag":87,"props":215,"children":216},{},[217,223],{"type":75,"tag":99,"props":218,"children":220},{"className":219},[],[221],{"type":80,"value":222},"p=reject",{"type":80,"value":224}," asks them to refuse it.",{"type":75,"tag":76,"props":226,"children":227},{},[228,230,236,238,244],{"type":80,"value":229},"Quarantine or reject plus a ",{"type":75,"tag":99,"props":231,"children":233},{"className":232},[],[234],{"type":80,"value":235},"rua=",{"type":80,"value":237}," address is green. ",{"type":75,"tag":99,"props":239,"children":241},{"className":240},[],[242],{"type":80,"value":243},"rua",{"type":80,"value":245}," is where receivers send aggregate reports, which show whether your own senders pass before you enforce.",{"type":75,"tag":76,"props":247,"children":248},{},[249,257],{"type":75,"tag":141,"props":250,"children":254},{"href":251,"rel":252},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc9989",[253],"nofollow",[255],{"type":80,"value":256},"RFC 9989",{"type":80,"value":258}," replaced the original DMARC spec, RFC 7489, in May 2026, and changed a few tags:",{"type":75,"tag":83,"props":260,"children":261},{},[262,305,345,356],{"type":75,"tag":87,"props":263,"children":264},{},[265,271,273,279,281,287,289,295,297,303],{"type":75,"tag":99,"props":266,"children":268},{"className":267},[],[269],{"type":80,"value":270},"pct",{"type":80,"value":272}," is gone. ",{"type":75,"tag":99,"props":274,"children":276},{"className":275},[],[277],{"type":80,"value":278},"pct=0",{"type":80,"value":280}," becomes ",{"type":75,"tag":99,"props":282,"children":284},{"className":283},[],[285],{"type":80,"value":286},"t=y",{"type":80,"value":288},", ",{"type":75,"tag":99,"props":290,"children":292},{"className":291},[],[293],{"type":80,"value":294},"pct=100",{"type":80,"value":296}," can be deleted, and partial values like ",{"type":75,"tag":99,"props":298,"children":300},{"className":299},[],[301],{"type":80,"value":302},"pct=50",{"type":80,"value":304}," have no replacement.",{"type":75,"tag":87,"props":306,"children":307},{},[308,313,315,321,323,329,331,336,337,343],{"type":75,"tag":99,"props":309,"children":311},{"className":310},[],[312],{"type":80,"value":286},{"type":80,"value":314}," is the new test mode: receivers handle ",{"type":75,"tag":99,"props":316,"children":318},{"className":317},[],[319],{"type":80,"value":320},"reject",{"type":80,"value":322}," as ",{"type":75,"tag":99,"props":324,"children":326},{"className":325},[],[327],{"type":80,"value":328},"quarantine",{"type":80,"value":330}," and ",{"type":75,"tag":99,"props":332,"children":334},{"className":333},[],[335],{"type":80,"value":328},{"type":80,"value":322},{"type":75,"tag":99,"props":338,"children":340},{"className":339},[],[341],{"type":80,"value":342},"none",{"type":80,"value":344},".",{"type":75,"tag":87,"props":346,"children":347},{},[348,354],{"type":75,"tag":99,"props":349,"children":351},{"className":350},[],[352],{"type":80,"value":353},"np",{"type":80,"value":355},", now part of the main spec, sets the policy for subdomains that don't exist.",{"type":75,"tag":87,"props":357,"children":358},{},[359,365,366,372],{"type":75,"tag":99,"props":360,"children":362},{"className":361},[],[363],{"type":80,"value":364},"rf",{"type":80,"value":330},{"type":75,"tag":99,"props":367,"children":369},{"className":368},[],[370],{"type":80,"value":371},"ri",{"type":80,"value":373}," are historic, and receivers ignore them.",{"type":75,"tag":76,"props":375,"children":376},{},[377],{"type":80,"value":378},"Policy lookup now walks up the DNS tree instead of using the Public Suffix List, so a subdomain without its own record shows its parent's as \"inherited from\".",{"data":380,"body":381},{},{"type":72,"children":382},[383,403,422,441],{"type":75,"tag":76,"props":384,"children":385},{},[386,388,395,397,402],{"type":80,"value":387},"Since February 1, 2024, ",{"type":75,"tag":141,"props":389,"children":392},{"href":390,"rel":391},"https:\u002F\u002Fsupport.google.com\u002Fa\u002Fanswer\u002F81126",[253],[393],{"type":80,"value":394},"Gmail",{"type":80,"value":396}," requires every sender to set up SPF or DKIM. If you send more than 5,000 messages a day to Gmail accounts, you need SPF, DKIM and DMARC, and your From domain has to align with SPF or DKIM. The DMARC policy can be ",{"type":75,"tag":99,"props":398,"children":400},{"className":399},[],[401],{"type":80,"value":342},{"type":80,"value":344},{"type":75,"tag":76,"props":404,"children":405},{},[406,413,415,420],{"type":75,"tag":141,"props":407,"children":410},{"href":408,"rel":409},"https:\u002F\u002Fsenders.yahooinc.com\u002Fbest-practices\u002F",[253],[411],{"type":80,"value":412},"Yahoo",{"type":80,"value":414}," asks the same minimum of everyone: SPF or DKIM. Bulk senders need both, plus a valid DMARC policy of at least ",{"type":75,"tag":99,"props":416,"children":418},{"className":417},[],[419],{"type":80,"value":200},{"type":80,"value":421},", and DMARC has to pass. Relaxed alignment is fine. Yahoo doesn't put a number on \"bulk\".",{"type":75,"tag":76,"props":423,"children":424},{},[425,432,434,439],{"type":75,"tag":141,"props":426,"children":429},{"href":427,"rel":428},"https:\u002F\u002Fpostmaster.outlook.com\u002Fpolicies.aspx",[253],[430],{"type":80,"value":431},"Microsoft",{"type":80,"value":433}," followed on May 5, 2025, for Outlook.com: domains sending more than 5,000 emails a day must pass SPF and DKIM and publish DMARC at ",{"type":75,"tag":99,"props":435,"children":437},{"className":436},[],[438],{"type":80,"value":200},{"type":80,"value":440}," or stricter, aligned with SPF or DKIM. Mail that doesn't comply goes to junk and may be rejected.",{"type":75,"tag":76,"props":442,"children":443},{},[444,446,451,453,459],{"type":80,"value":445},"So ",{"type":75,"tag":99,"props":447,"children":449},{"className":448},[],[450],{"type":80,"value":200},{"type":80,"value":452}," is the floor at all three. Our take: publish SPF, DKIM and DMARC on every domain you send from, whatever your volume. With ",{"type":75,"tag":141,"props":454,"children":456},{"href":455},"\u002Fblog\u002Ftransactional-email-for-multiple-domains",[457],{"type":80,"value":458},"transactional email across domains",{"type":80,"value":460},", each domain needs its own set.",{"data":462,"body":463},{},{"type":72,"children":464},[465,470,475,582,615],{"type":75,"tag":76,"props":466,"children":467},{},[468],{"type":80,"value":469},"If you own several domains, some are probably parked. Without records, anyone can send mail that claims to come from them, and receivers have no policy telling them to refuse it.",{"type":75,"tag":76,"props":471,"children":472},{},[473],{"type":80,"value":474},"Three records lock a parked domain down:",{"type":75,"tag":476,"props":477,"children":478},"table",{},[479,503],{"type":75,"tag":480,"props":481,"children":482},"thead",{},[483],{"type":75,"tag":484,"props":485,"children":486},"tr",{},[487,493,498],{"type":75,"tag":488,"props":489,"children":490},"th",{},[491],{"type":80,"value":492},"Host",{"type":75,"tag":488,"props":494,"children":495},{},[496],{"type":80,"value":497},"Type",{"type":75,"tag":488,"props":499,"children":500},{},[501],{"type":80,"value":502},"Value",{"type":75,"tag":504,"props":505,"children":506},"tbody",{},[507,534,558],{"type":75,"tag":484,"props":508,"children":509},{},[510,520,525],{"type":75,"tag":511,"props":512,"children":513},"td",{},[514],{"type":75,"tag":99,"props":515,"children":517},{"className":516},[],[518],{"type":80,"value":519},"yourdomain.com",{"type":75,"tag":511,"props":521,"children":522},{},[523],{"type":80,"value":524},"TXT",{"type":75,"tag":511,"props":526,"children":527},{},[528],{"type":75,"tag":99,"props":529,"children":531},{"className":530},[],[532],{"type":80,"value":533},"v=spf1 -all",{"type":75,"tag":484,"props":535,"children":536},{},[537,545,549],{"type":75,"tag":511,"props":538,"children":539},{},[540],{"type":75,"tag":99,"props":541,"children":543},{"className":542},[],[544],{"type":80,"value":104},{"type":75,"tag":511,"props":546,"children":547},{},[548],{"type":80,"value":524},{"type":75,"tag":511,"props":550,"children":551},{},[552],{"type":75,"tag":99,"props":553,"children":555},{"className":554},[],[556],{"type":80,"value":557},"v=DMARC1; p=reject;",{"type":75,"tag":484,"props":559,"children":560},{},[561,569,573],{"type":75,"tag":511,"props":562,"children":563},{},[564],{"type":75,"tag":99,"props":565,"children":567},{"className":566},[],[568],{"type":80,"value":519},{"type":75,"tag":511,"props":570,"children":571},{},[572],{"type":80,"value":132},{"type":75,"tag":511,"props":574,"children":575},{},[576],{"type":75,"tag":99,"props":577,"children":579},{"className":578},[],[580],{"type":80,"value":581},"0 .",{"type":75,"tag":76,"props":583,"children":584},{},[585,590,592,597,599,604,606,613],{"type":75,"tag":99,"props":586,"children":588},{"className":587},[],[589],{"type":80,"value":533},{"type":80,"value":591}," says no server may send as the domain, ",{"type":75,"tag":99,"props":593,"children":595},{"className":594},[],[596],{"type":80,"value":222},{"type":80,"value":598}," tells receivers to refuse anything that tries, and the null MX (",{"type":75,"tag":99,"props":600,"children":602},{"className":601},[],[603],{"type":80,"value":581},{"type":80,"value":605},", from ",{"type":75,"tag":141,"props":607,"children":610},{"href":608,"rel":609},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc7505",[253],[611],{"type":80,"value":612},"RFC 7505",{"type":80,"value":614},") says it accepts no mail, so senders fail right away instead of retrying.",{"type":75,"tag":76,"props":616,"children":617},{},[618,620,626],{"type":80,"value":619},"The checker suggests this set when a domain has no MX, SPF or DMARC. If you later want mail on one of them, our guide to ",{"type":75,"tag":141,"props":621,"children":623},{"href":622},"\u002Fblog\u002Femail-hosting-for-multiple-domains",[624],{"type":80,"value":625},"email hosting for several domains",{"type":80,"value":627}," compares the options.",{"data":629,"body":630},{},{"type":72,"children":631},[632],{"type":75,"tag":76,"props":633,"children":634},{},[635,637,642,644,650],{"type":80,"value":636},"Paste your domain in the box at the top of this page and click Check domains. To check by hand, look up the TXT record at ",{"type":75,"tag":99,"props":638,"children":640},{"className":639},[],[641],{"type":80,"value":104},{"type":80,"value":643},", for example with ",{"type":75,"tag":99,"props":645,"children":647},{"className":646},[],[648],{"type":80,"value":649},"dig TXT _dmarc.yourdomain.com",{"type":80,"value":651},". If nothing comes back, the domain has no DMARC record.",{"data":653,"body":654},{},{"type":72,"children":655},[656],{"type":75,"tag":76,"props":657,"children":658},{},[659,661,666,668,674,676,682,684,689,691,696],{"type":80,"value":660},"The record only tells you the policy. Whether your mail passes shows up in two places: the aggregate reports sent to your ",{"type":75,"tag":99,"props":662,"children":664},{"className":663},[],[665],{"type":80,"value":243},{"type":80,"value":667}," address, and the headers of a message you send, where the Authentication-Results line says ",{"type":75,"tag":99,"props":669,"children":671},{"className":670},[],[672],{"type":80,"value":673},"dmarc=pass",{"type":80,"value":675}," or ",{"type":75,"tag":99,"props":677,"children":679},{"className":678},[],[680],{"type":80,"value":681},"dmarc=fail",{"type":80,"value":683},". Add ",{"type":75,"tag":99,"props":685,"children":687},{"className":686},[],[688],{"type":80,"value":243},{"type":80,"value":690}," and read about a week of reports before you move past ",{"type":75,"tag":99,"props":692,"children":694},{"className":693},[],[695],{"type":80,"value":200},{"type":80,"value":344},{"data":698,"body":699},{},{"type":72,"children":700},[701],{"type":75,"tag":76,"props":702,"children":703},{},[704,706,712,714,720,722,727],{"type":80,"value":705},"Add a TXT record with the host ",{"type":75,"tag":99,"props":707,"children":709},{"className":708},[],[710],{"type":80,"value":711},"_dmarc",{"type":80,"value":713}," and the value ",{"type":75,"tag":99,"props":715,"children":717},{"className":716},[],[718],{"type":80,"value":719},"v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com",{"type":80,"value":721},", using an address you actually read. Most DNS panels add your domain to the host for you, so type only ",{"type":75,"tag":99,"props":723,"children":725},{"className":724},[],[726],{"type":80,"value":711},{"type":80,"value":728},". Then check the domain here again to confirm it's live.",{"data":730,"body":731},{},{"type":72,"children":732},[733],{"type":75,"tag":76,"props":734,"children":735},{},[736,738,743,745,750,751,756],{"type":80,"value":737},"For the Gmail, Yahoo and Outlook.com bulk-sender rules, yes: all three accept ",{"type":75,"tag":99,"props":739,"children":741},{"className":740},[],[742],{"type":80,"value":200},{"type":80,"value":744},". It doesn't stop anyone from spoofing your domain, though, because mail that fails DMARC still gets delivered. Treat it as the monitoring step before ",{"type":75,"tag":99,"props":746,"children":748},{"className":747},[],[749],{"type":80,"value":328},{"type":80,"value":675},{"type":75,"tag":99,"props":752,"children":754},{"className":753},[],[755],{"type":80,"value":320},{"type":80,"value":344},{"data":758,"body":759},{},{"type":72,"children":760},[761],{"type":75,"tag":76,"props":762,"children":763},{},[764,766,771,773,778,780,785,787,792],{"type":80,"value":765},"RFC 9989, published in May 2026, removed it. If you used ",{"type":75,"tag":99,"props":767,"children":769},{"className":768},[],[770],{"type":80,"value":278},{"type":80,"value":772}," to test, switch to ",{"type":75,"tag":99,"props":774,"children":776},{"className":775},[],[777],{"type":80,"value":286},{"type":80,"value":779},". If your record has ",{"type":75,"tag":99,"props":781,"children":783},{"className":782},[],[784],{"type":80,"value":294},{"type":80,"value":786},", delete it, since 100 was the default anyway. A partial rollout like ",{"type":75,"tag":99,"props":788,"children":790},{"className":789},[],[791],{"type":80,"value":302},{"type":80,"value":793}," has no replacement, so receivers that follow the new spec apply your policy to all failing mail.",{"data":795,"body":796},{},{"type":72,"children":797},[798],{"type":75,"tag":76,"props":799,"children":800},{},[801],{"type":80,"value":33},{"data":803,"body":804},{},{"type":72,"children":805},[806],{"type":75,"tag":76,"props":807,"children":808},{},[809,811,816,818,823,824,829,831,836],{"type":80,"value":810},"Yes. Without it, anyone can send mail that claims to come from that domain. Publish ",{"type":75,"tag":99,"props":812,"children":814},{"className":813},[],[815],{"type":80,"value":557},{"type":80,"value":817}," at ",{"type":75,"tag":99,"props":819,"children":821},{"className":820},[],[822],{"type":80,"value":711},{"type":80,"value":288},{"type":75,"tag":99,"props":825,"children":827},{"className":826},[],[828],{"type":80,"value":533},{"type":80,"value":830}," on the domain itself and a null MX (",{"type":75,"tag":99,"props":832,"children":834},{"className":833},[],[835],{"type":80,"value":581},{"type":80,"value":837},"), and it's locked down.",{"data":839,"body":840},{},{"type":72,"children":841},[842],{"type":75,"tag":76,"props":843,"children":844},{},[845,847,853],{"type":80,"value":846},"No. Each check runs live against public DNS (Cloudflare's resolver, with Google's as a fallback) and the result goes straight back to your browser. We don't save the domains or log them, and our analytics only records how many you checked, never which ones. If you share a link to your results, the domains sit after the ",{"type":75,"tag":99,"props":848,"children":850},{"className":849},[],[851],{"type":80,"value":852},"#",{"type":80,"value":854}," in the URL, and browsers don't send that part to our server.",{"data":856,"body":857},{},{"type":72,"children":858},[859,866,877,890,908,914,949,957,963,1011,1032],{"type":75,"tag":860,"props":861,"children":863},"h3",{"id":862},"no-dmarc-record",[864],{"type":80,"value":865},"No DMARC record",{"type":75,"tag":76,"props":867,"children":868},{},[869,870,875],{"type":80,"value":705},{"type":75,"tag":99,"props":871,"children":873},{"className":872},[],[874],{"type":80,"value":711},{"type":80,"value":876}," and this value:",{"type":75,"tag":878,"props":879,"children":885},"pre",{"className":880,"code":881,"language":882,"meta":883,"style":884},"language-txt","v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com\n","txt","","undefined",[886],{"type":75,"tag":99,"props":887,"children":888},{"__ignoreMap":883},[889],{"type":80,"value":881},{"type":75,"tag":76,"props":891,"children":892},{},[893,895,900,902,907],{"type":80,"value":894},"Use an address you actually read. After a week or two of reports where your real senders pass, move to ",{"type":75,"tag":99,"props":896,"children":898},{"className":897},[],[899],{"type":80,"value":211},{"type":80,"value":901},", then ",{"type":75,"tag":99,"props":903,"children":905},{"className":904},[],[906],{"type":80,"value":222},{"type":80,"value":344},{"type":75,"tag":860,"props":909,"children":911},{"id":910},"two-spf-records",[912],{"type":80,"value":913},"Two SPF records",{"type":75,"tag":76,"props":915,"children":916},{},[917,919,924,926,932,934,940,941,947],{"type":80,"value":918},"A domain can only have one SPF record. With two, SPF fails with a permanent error for every message. Merge them into one ",{"type":75,"tag":99,"props":920,"children":922},{"className":921},[],[923],{"type":80,"value":122},{"type":80,"value":925}," with every ",{"type":75,"tag":99,"props":927,"children":929},{"className":928},[],[930],{"type":80,"value":931},"include",{"type":80,"value":933}," and a single ",{"type":75,"tag":99,"props":935,"children":937},{"className":936},[],[938],{"type":80,"value":939},"~all",{"type":80,"value":675},{"type":75,"tag":99,"props":942,"children":944},{"className":943},[],[945],{"type":80,"value":946},"-all",{"type":80,"value":948},":",{"type":75,"tag":878,"props":950,"children":952},{"className":880,"code":951,"language":882,"meta":883,"style":884},"Before, two records:\nv=spf1 include:_spf.google.com ~all\nv=spf1 include:mailgun.org ~all\n\nAfter, one record:\nv=spf1 include:_spf.google.com include:mailgun.org ~all\n",[953],{"type":75,"tag":99,"props":954,"children":955},{"__ignoreMap":883},[956],{"type":80,"value":951},{"type":75,"tag":860,"props":958,"children":960},{"id":959},"too-many-spf-lookups",[961],{"type":80,"value":962},"Too many SPF lookups",{"type":75,"tag":76,"props":964,"children":965},{},[966,973,975,980,981,987,989,995,996,1002,1004,1010],{"type":75,"tag":141,"props":967,"children":970},{"href":968,"rel":969},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc7208",[253],[971],{"type":80,"value":972},"RFC 7208",{"type":80,"value":974}," caps SPF at 10 DNS lookups, counted through nested includes, and at 2 lookups that come back empty. Past either limit, SPF fails. To get under, remove includes you no longer use, swap ",{"type":75,"tag":99,"props":976,"children":978},{"className":977},[],[979],{"type":80,"value":141},{"type":80,"value":330},{"type":75,"tag":99,"props":982,"children":984},{"className":983},[],[985],{"type":80,"value":986},"mx",{"type":80,"value":988}," for the ",{"type":75,"tag":99,"props":990,"children":992},{"className":991},[],[993],{"type":80,"value":994},"ip4",{"type":80,"value":330},{"type":75,"tag":99,"props":997,"children":999},{"className":998},[],[1000],{"type":80,"value":1001},"ip6",{"type":80,"value":1003}," addresses behind them, and drop ",{"type":75,"tag":99,"props":1005,"children":1007},{"className":1006},[],[1008],{"type":80,"value":1009},"ptr",{"type":80,"value":344},{"type":75,"tag":76,"props":1012,"children":1013},{},[1014,1016,1022,1024,1030],{"type":80,"value":1015},"Some senders, like Postmark, use a Return-Path subdomain with its own SPF and don't need your root record at all. Mailyond works the same way: each domain you connect takes ",{"type":75,"tag":141,"props":1017,"children":1019},{"href":1018},"\u002F#how-it-works",[1020],{"type":80,"value":1021},"one 5-minute DNS setup",{"type":80,"value":1023}," of three records (DKIM, Return-Path and MX), and your root SPF record stays as it is. For ",{"type":75,"tag":141,"props":1025,"children":1027},{"href":1026},"\u002Fblog\u002Fnamecheap-email-setup",[1028],{"type":80,"value":1029},"a full SPF, DKIM and DMARC record set on registrar DNS",{"type":80,"value":1031},", see our Namecheap guide.",{"type":75,"tag":1033,"props":1034,"children":1035},"style",{},[1036],{"type":80,"value":883},1791706041142]