XiaTools
Email tool

DMARC Checker

Check the DMARC record of a domain and see its policy, reporting addresses and alignment settings.

The XiaTools DMARC Checker is a free online utility designed to query and validate the Domain-based Message Authentication, Reporting, and Conformance (DMARC) record of any given domain. By entering your domain name, you can instantly inspect your current email security configuration, policy enforcement level, and reporting destinations.

What is it

A DMARC record is a TXT record published in your domain's DNS settings that tells receiving mail servers how to handle emails sent from your domain. It works in tandem with Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) to verify that an incoming message genuinely originates from your organization. When an email fails SPF or DKIM checks, DMARC instructs the receiving server on whether to deliver, quarantine, or completely reject the message based on your specified policy. Furthermore, DMARC provides a mechanism for receiving servers to send forensic and aggregate reports back to you, detailing traffic sources and potential spoofing attempts.

Why it matters

Implementing DMARC is crucial for protecting your brand's reputation and preventing malicious actors from sending phishing emails using your domain name. Without a strict DMARC policy, cybercriminals can easily forge your sender address, deceiving customers, partners, and employees into trusting fraudulent messages. Internet service providers increasingly flag or block unauthenticated emails, meaning a missing or misconfigured DMARC record can severely damage your email deliverability rates. By monitoring DMARC aggregate reports, you gain complete visibility into your email ecosystem, allowing you to identify all legitimate sending services and detect unauthorized infrastructure attempting to abuse your domain.

How to use this tool

  1. Navigate to the XiaTools DMARC Checker page.
  2. Locate the input field designated for the domain name.
  3. Enter your domain name in the box, omitting any prefixes like "http://" or "https://" (for example, example.com).
  4. Press the Check button to initiate a live DNS query for your domain's DMARC record.
  5. Review the parsed output displayed on the screen to analyze your current configuration.

How to read the results

When you check a domain like example.com, our tool queries the DNS for the TXT record located at _dmarc.example.com and breaks down each tag. Here is an explanation of the values and settings you will see in a typical realistic output:

Common problems and how to fix them

Missing DMARC Record

If the tool reports that no DMARC record exists, you must create a TXT record in your DNS zone manager. Create a new TXT record with the host name _dmarc and a basic monitoring value to start safely.

_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com;"

Syntax and Typo Errors

DMARC records are strictly parsed, and a simple typo in a tag name will cause the record to be ignored by receiving servers. Ensure all tags are lowercase, separated by semicolons, and prefixed with v=DMARC1;.

Invalid Reporting URIs

If your rua or ruf addresses point to an external domain that has not authorized your reports, the reports will fail to deliver. Ensure external domains include a DMARC external destination verification TXT record in their own DNS.

Best practices

Start your DMARC journey conservatively by setting your policy to p=none alongside an aggregate reporting address (rua). Monitor these reports for several weeks to identify all legitimate third-party senders, such as marketing platforms and helpdesk software, ensuring their SPF and DKIM signatures are correctly aligned. Once you are confident that all legitimate mail is authenticating successfully, incrementally move your policy to p=quarantine, and finally enforce full protection with p=reject. Regularly review your aggregate reports to catch unauthorized sending attempts and maintain optimal email deliverability.

Frequently asked questions

What is a DMARC record?

A DMARC record is a DNS TXT record that tells receiving mail servers how to handle emails that fail SPF or DKIM authentication checks. It also allows domain owners to receive reports about emails sent using their domain.

Why is my DMARC record showing as not found?

This means your domain does not have a TXT record published at the mandatory _dmarc subdomain. To fix this, you need to add a DMARC record through your DNS hosting provider.

Should I start with p=none, p=quarantine, or p=reject?

You should always start with p=none. This monitoring-only mode allows you to collect report data and identify legitimate mail sources without risking the delivery of your valid emails.

What is the difference between rua and ruf addresses?

The rua tag specifies where aggregate XML reports containing daily summary statistics are sent. The ruf tag specifies where individual forensic reports are sent in real-time when an email fails authentication.

Why are my DMARC reports not arriving?

Ensure that your email address in the rua or ruf tag is active and correctly formatted as a mailto URI. If you are sending reports to a third-party domain, they must also publish a DNS record authorizing your domain to send reports to them.

How long does it take for DNS changes to reflect in the DMARC checker?

DNS changes typically propagate globally within a few minutes to a few hours, depending on your DNS provider's Time To Live (TTL) settings. Once propagated, our tool will display your updated record.

DMARC Checker guides

Related tools