XiaTools
Email tool

DMARC Record Generator

Create a DMARC record with the right policy, reporting address and alignment for your domain.

Create your DMARC record

The XiaTools DMARC Record Generator helps you build a custom Domain-based Message Authentication, Reporting, and Conformance record for your domain's DNS settings. It guides you through policy selection, reporting endpoints, and alignment options to generate a ready-to-publish TXT record.

What is a DMARC Record?

A DMARC record is a TXT record published in your Domain Name System that instructs receiving mail servers on how to handle emails sent from your domain. It relies on two underlying standards: Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). When an email arrives, the receiving server checks if it passes SPF and DKIM checks, and whether those authenticated domains align with the domain in the "From" header.

Without DMARC, malicious actors can easily spoof your domain to send phishing emails that appear to come from your organization. A DMARC policy tells the receiving mail server what to do when authentication fails—whether to let it through regardless (none), quarantine it into the spam folder (quarantine), or reject it outright (reject). It also enables aggregate and forensic reporting so you can see every server sending mail on your domain's behalf.

Why DMARC Matters for Email Security

Email spoofing damages brand reputation and allows cybercriminals to target your customers, partners, and employees. Implementing DMARC stops unauthorized senders in their tracks and gives you complete visibility into your email ecosystem.

Before DMARC, domain administrators had no way to receive feedback on unauthorized email traffic. DMARC reporting transforms this blind spot into actionable data. You receive daily XML files detailing every IP address attempting to send mail as your domain. This visibility is essential for identifying third-party marketing tools or IT services that need proper SPF or DKIM configuration before you enforce stricter policies.

How to Use This Tool

  1. Navigate to the XiaTools DMARC Record Generator page.
  2. Enter your domain name into the input box.
  3. Select your desired DMARC policy (none, quarantine, or reject).
  4. Configure your aggregate and forensic reporting email addresses.
  5. Adjust percentage flags, subdomain policies, and alignment settings as needed.
  6. Press Check to generate your custom DMARC TXT record.

How to Read the Results

Once you press Check, the tool outputs a complete DNS TXT record string that you can copy and paste directly into your DNS zone manager.

For example, if you generate a record for example.com with a quarantine policy and reporting enabled, the output looks like this:

v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; ruf=mailto:dmarc-forensics@example.com; pct=100; sp=reject; aspf=s; adkim=s;

Here is what each tag in the generated output means:

Common Problems and How to Fix Them

Multiple DMARC Records

Publishing more than one DMARC record in your DNS zone causes receiving mail servers to ignore your policy entirely.

_dmarc.example.com. IN TXT "v=DMARC1; p=none;"
_dmarc.example.com. IN TXT "v=DMARC1; p=reject;"

To fix this, delete all extra entries and maintain exactly one _dmarc TXT record per domain.

Syntax Errors in Email URIs

Invalid reporting addresses will cause receiving servers to drop reports or flag your record as malformed. Always prefix your email addresses with mailto:.

_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=dmarc-reports@example.com;"

Correct the syntax by ensuring the mailto: scheme is present:

_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com;"

Mailbox Flooding from Forensic Reports

Setting up forensic reporting (ruf) can generate massive volumes of individual emails for every failed message, often hitting mailbox storage limits or triggering spam filters.

To fix this, rely primarily on aggregate reports (rua) for routine monitoring, and only enable forensic reports when actively debugging specific delivery issues.

Best Practices

Always start your DMARC journey with a monitoring policy (p=none). This ensures that legitimate emails are not accidentally blocked while you analyze your aggregate reports and map out all authorized sending infrastructure.

Ensure your SPF and DKIM records are fully functional and properly aligned before stepping your policy up to quarantine or reject. Gradually increase your percentage tag (pct) if you want to test stricter policies on a small subset of traffic before enforcing them globally. Finally, use an external mailbox dedicated strictly to DMARC XML reports to keep your primary inbox clean and organized.

Frequently asked questions

What is a DMARC record?

A DMARC record is a DNS TXT record that tells receiving mail servers how to verify emails sent from your domain using SPF and DKIM, and what action to take if authentication fails.

Where should I publish the generated DMARC record?

You must publish the record as a TXT record in your DNS zone manager under the host name _dmarc.yourdomain.com.

What policy should I choose when starting out?

You should always start with p=none. This policy does not block any mail; instead, it allows you to collect reports and identify all legitimate senders without risking delivery disruptions.

What is the difference between rua and ruf?

The rua tag specifies the destination for daily aggregate XML reports summarizing all mail traffic, while the ruf tag specifies where to send immediate forensic failure reports for individual failed emails.

Why are aggregate reports sent to an external address?

Aggregate reports are often parsed by third-party analytics tools or dedicated monitoring mailboxes to keep raw XML data separate from your primary corporate email stream.

Can I use DMARC without SPF or DKIM?

DMARC relies entirely on SPF and DKIM to function. At least one of these protocols must be properly configured and aligned for DMARC to pass.

DMARC Record Generator guides

Related tools