The XiaTools DMARC Record Generator helps you build a custom Domain-based Message Authentication, Reporting, and Conformance record for your domain's DNS settings. It guides you through policy selection, reporting endpoints, and alignment options to generate a ready-to-publish TXT record.
What is a DMARC Record?
A DMARC record is a TXT record published in your Domain Name System that instructs receiving mail servers on how to handle emails sent from your domain. It relies on two underlying standards: Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM). When an email arrives, the receiving server checks if it passes SPF and DKIM checks, and whether those authenticated domains align with the domain in the "From" header.
Without DMARC, malicious actors can easily spoof your domain to send phishing emails that appear to come from your organization. A DMARC policy tells the receiving mail server what to do when authentication fails—whether to let it through regardless (none), quarantine it into the spam folder (quarantine), or reject it outright (reject). It also enables aggregate and forensic reporting so you can see every server sending mail on your domain's behalf.
Why DMARC Matters for Email Security
Email spoofing damages brand reputation and allows cybercriminals to target your customers, partners, and employees. Implementing DMARC stops unauthorized senders in their tracks and gives you complete visibility into your email ecosystem.
Before DMARC, domain administrators had no way to receive feedback on unauthorized email traffic. DMARC reporting transforms this blind spot into actionable data. You receive daily XML files detailing every IP address attempting to send mail as your domain. This visibility is essential for identifying third-party marketing tools or IT services that need proper SPF or DKIM configuration before you enforce stricter policies.
How to Use This Tool
- Navigate to the XiaTools DMARC Record Generator page.
- Enter your domain name into the input box.
- Select your desired DMARC policy (
none,quarantine, orreject). - Configure your aggregate and forensic reporting email addresses.
- Adjust percentage flags, subdomain policies, and alignment settings as needed.
- Press Check to generate your custom DMARC TXT record.
How to Read the Results
Once you press Check, the tool outputs a complete DNS TXT record string that you can copy and paste directly into your DNS zone manager.
For example, if you generate a record for example.com with a quarantine policy and reporting enabled, the output looks like this:
v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com; ruf=mailto:dmarc-forensics@example.com; pct=100; sp=reject; aspf=s; adkim=s;
Here is what each tag in the generated output means:
v=DMARC1: The protocol version. This must always be the first tag and set to DMARC1.p=quarantine: The core policy for the domain. It tells receiving servers to send unauthenticated emails to the spam folder.rua=mailto:dmarc-reports@example.com: The URI where aggregate XML reports are sent.ruf=mailto:dmarc-forensics@example.com: The URI where individual forensic failure reports are sent.pct=100: The percentage of messages filtered by the policy. Setting this to 100 applies the policy to all mail.sp=reject: The policy specifically applied to subdomains, overriding the main policy for items likesub.example.com.aspf=s: Strict SPF alignment mode. The header From domain must match the return-path domain exactly.adkim=s: Strict DKIM alignment mode. The header From domain must match the signing d= domain exactly.
Common Problems and How to Fix Them
Multiple DMARC Records
Publishing more than one DMARC record in your DNS zone causes receiving mail servers to ignore your policy entirely.
_dmarc.example.com. IN TXT "v=DMARC1; p=none;"
_dmarc.example.com. IN TXT "v=DMARC1; p=reject;"
To fix this, delete all extra entries and maintain exactly one _dmarc TXT record per domain.
Syntax Errors in Email URIs
Invalid reporting addresses will cause receiving servers to drop reports or flag your record as malformed. Always prefix your email addresses with mailto:.
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=dmarc-reports@example.com;"
Correct the syntax by ensuring the mailto: scheme is present:
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com;"
Mailbox Flooding from Forensic Reports
Setting up forensic reporting (ruf) can generate massive volumes of individual emails for every failed message, often hitting mailbox storage limits or triggering spam filters.
To fix this, rely primarily on aggregate reports (rua) for routine monitoring, and only enable forensic reports when actively debugging specific delivery issues.
Best Practices
Always start your DMARC journey with a monitoring policy (p=none). This ensures that legitimate emails are not accidentally blocked while you analyze your aggregate reports and map out all authorized sending infrastructure.
Ensure your SPF and DKIM records are fully functional and properly aligned before stepping your policy up to quarantine or reject. Gradually increase your percentage tag (pct) if you want to test stricter policies on a small subset of traffic before enforcing them globally. Finally, use an external mailbox dedicated strictly to DMARC XML reports to keep your primary inbox clean and organized.