XiaTools

How to Perform a Bulk DMARC Check Across Client Domains

Updated 11 Oct 2026

Performing a comprehensive email security audit requires verifying authentication records across multiple properties simultaneously. Manually querying individual zones wastes valuable engineering time and introduces human error into compliance reporting. A DMARC Checker simplifies this workflow by allowing you to inspect policy compliance, alignment settings, and reporting destinations for single domains instantly. However, managing portfolios for dozens or hundreds of clients demands an automated, scriptable approach to bulk DMARC validation.

Understanding DMARC Records and Why Bulk Auditing Matters

Domain-based Message Authentication, Reporting, and Conformance (DMARC) relies on DNS TXT records to instruct receiving mail servers on how to handle emails that fail SPF (Sender Policy Framework) or DKIM (DomainKeys Identified Mail) checks. A standard DMARC record lives at the _dmarc.example.com subdomain and defines a policy (p=none, p=quarantine, or p=reject), reporting URIs (rua, ruf), and percentage enforcement flags (pct).

When managing email infrastructure for multiple brands, agencies, or enterprise clients, configuration drift is a constant threat. Domains expire, DNS providers change, and marketing teams deploy new third-party mailing services without updating authentication policies. Running a bulk dmarc checker tool process allows you to:

  • Identify unprotected domains operating with missing policies or p=none status.
  • Verify that aggregate reporting (rua) endpoints are active and collecting telemetry.
  • Ensure SPF and DKIM alignment settings meet current industry standards.
  • Generate automated compliance reports for stakeholders or cybersecurity insurance.

Preparing Your Domain List for Bulk Verification

Before executing queries, compile your target domains into a clean, structured text file or comma-separated values (CSV) list. Remove protocol prefixes like https:// and trailing slashes. Your list should look strictly like this:

example.com
client-domain-one.test
client-domain-two.test

Keep in mind that documentation networks and test zones such as example.com or 192.0.2.0/24 will not yield live production records, but they serve as excellent test beds for validating your automation scripts before pointing them at real client assets.

Step-by-Step Guide: Building and Running a Bulk DMARC Script

The most reliable way to check DMARC records in bulk is by leveraging command-line utilities combined with scripting languages like PowerShell or Bash. Below are implementation examples using standard tools available on modern operating systems.

Method 1: Bash and Dig for Linux and macOS Systems

If you operate in a Unix-like environment, you can iterate through a text file of domains using a basic while loop paired with the dig utility.

  1. Create a file named domains.txt containing your list of target domains, one per line.
  2. Open your terminal and run the following script:
while IFS= read -r domain; do
  echo "Checking: _dmarc.$domain"
  dig +short TXT "_dmarc.$domain"
  echo "----------------------------------------"
done < domains.txt

Sample output from the execution:

Checking: _dmarc.example.com
"v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; pct=100"
----------------------------------------
Checking: _dmarc.client-domain-one.test

----------------------------------------

If the output is empty, the target domain lacks a DMARC record entirely.

Method 2: PowerShell for Windows Administrators

Windows administrators can use PowerShell to query DNS records via the built-in Resolve-DnsName cmdlet and output the results directly into a structured grid or CSV file.

  1. Save your domain list as C:\temp\domains.txt.
  2. Open PowerShell as an administrator and execute the following script:
$domains = Get-Content "C:\temp\domains.txt"
$results = foreach ($domain in $domains) {
    $recordName = "_dmarc.$domain"
    try {
        $txtRecord = Resolve-DnsName -Name $recordName -Type TXT -ErrorAction Stop
        $dmarcString = ($txtRecord.Strings -join "")
        [PSCustomObject]@{
            Domain = $domain
            Status = "Found"
            Record = $dmarcString
        }
    }
    catch {
        [PSCustomObject]@{
            Domain = $domain
            Status = "Missing"
            Record = $null
        }
    }
}
$results | Out-GridView
$results | Export-Csv -Path "C:\temp\dmarc-audit-results.csv" -NoTypeInformation

This script handles missing records gracefully without terminating the execution loop, logging a status of Missing for any domain failing to resolve a valid TXT entry.

Comparing Manual Checks vs. Bulk Automation

Feature Manual Single Check Bulk Scripted Check Automated API Monitor
Time Investment 2 minutes per domain Seconds for 100+ domains Continuous background monitoring
Error Rate High due to repetition Low if script is well-tested Minimal
Reporting Ad-hoc copy-paste CSV, JSON, or Grid output Dashboards and alert triggers
Scalability Poor (fails past 5 domains) Excellent for batch audits Ideal for enterprise portfolios

Analyzing DMARC Record Syntax and Common Values

Once you extract your bulk data, you must interpret the record values. A compliant and secure DMARC record contains specific tags separated by semicolons.

  • v=DMARC1: Identifies the protocol version. This tag is mandatory and must appear first.
  • p=...: Defines the policy for emails failing authentication. Options are none (monitoring only), quarantine (send to spam/junk), or reject (block outright).
  • rua=mailto:...: Specifies the email address where aggregate XML reports are sent.
  • pct=...: Applies the policy to a percentage of messages (defaults to 100 if omitted).

Common Mistakes and How to Fix Them

Auditing dozens of domains quickly reveals recurring configuration errors across different DNS providers (such as Cloudflare, Route 53, or cPanel).

  • Missing _dmarc Hostname Prefix: A frequent error is publishing the TXT record at the root domain (example.com) instead of the required subdomain (_dmarc.example.com). Ensure your DNS management console includes the literal _dmarc label.
  • Multiple DMARC Records: Publishing more than one DMARC record on a single domain invalidates the configuration under RFC specifications. Check your bulk output for duplicate entries and consolidate them into a single valid record.
  • Invalid Reporting URIs: If the rua email address resides on an external domain, that receiving domain must publish a corresponding DNS record granting permission to accept reports (e.g., target-domain._report._dmarc.external-domain.com IN TXT "v=DMARC1;"). Without this external validation, reporting data will be dropped.

Quick Checklist for Bulk DMARC Audits

  1. Compile a verified, de-duplicated list of client domains.
  2. Ensure your query script handles DNS timeouts and missing records gracefully.
  3. Run your bulk extraction tool and export results to a CSV format.
  4. Filter results by policy status (p=none vs p=reject).
  5. Flag domains with missing records or syntax errors for immediate remediation.
  6. Verify that active rua reporting addresses are monitored and receiving XML telemetry.

Frequently asked questions

What is the best policy setting to look for during a bulk DMARC audit?

During an audit, you should categorize domains based on their policy. A secure production domain should ideally use `p=reject`, while domains still undergoing testing or initial deployment typically use `p=quarantine` or `p=none`.

Why do some domains return multiple TXT records when queried?

Returning multiple TXT records usually indicates a misconfiguration where a domain administrator accidentally published conflicting DMARC or SPF entries. RFC guidelines state that receiving servers must ignore DMARC entirely if more than one record is found.

Can I check DMARC records using an API instead of command-line scripts?

Yes, many modern network monitoring platforms and DNS providers offer REST APIs that allow you to programmatically query DNS TXT records. This approach is ideal if you want to integrate DMARC checks into continuous integration pipelines or monitoring dashboards.

How often should I run a bulk DMARC check for client domains?

It is recommended to run a comprehensive bulk audit at least once a month or immediately following any major infrastructure migrations. Automated continuous monitors can also alert you instantly if a DNS record is accidentally deleted.

What does a missing DMARC record mean for an organization?

A missing DMARC record leaves a domain entirely unprotected against email spoofing and domain impersonation attacks. Without DMARC, malicious actors can send fraudulent emails appearing to originate from your brand without receiving mail servers blocking them.

Related articles

Free tools