Free tool

Check your DMARC recordand what it enforces.

Enter any domain. We read the DMARC record at _dmarc, parse every tag, and tell you what receivers will do when authentication fails. No account, no key.

What DMARC does

The instruction a receiver follows when authentication fails.

  • Policyp=none monitors and delivers, p=quarantine sends to spam, p=reject refuses. Monitoring protects nothing; it only reports.
  • Subdomain policysp= overrides the domain policy for subdomains. When absent it inherits from p=, but when set weaker, an attacker picks the subdomain.
  • Aggregate reportsrua= tells receivers where to send daily XML reports. Without it, nobody sees who is sending as the domain.
  • Percentagepct= applies the policy to only part of the mail. Useful during rollout, dangerous when left at a low value.

See all sender checks for the full list of SPF and DMARC findings we detect.