DMARC tells receivers what to do with mail that fails SPF and DKIM alignment and where to send reports. Since 2024 Gmail and Yahoo require a DMARC record for bulk senders, and Microsoft followed for Outlook.com in 2025.
Table of Contents
Moving from monitoring to enforcement
Start with p=none and an rua address, read the aggregate reports for two to four weeks, and fix every legitimate sender (CRM, invoicing, helpdesk, newsletters) so it passes SPF or DKIM with alignment. Then move to p=quarantine and finally p=reject.
Use the DMARC record generator on this site to build the record, and the SPF and DKIM checkers to confirm each sender is covered.
DMARC checker at a glance



How to use this tool
- Enter the domain from the visible From address, for example
example.com. Do not add_dmarc.yourself; the tool reads the TXT record at_dmarc.example.com. - Press Check DMARC. Only TXT records that start with
v=DMARC1count; anything else at that name is ignored, as receivers do. - Read the summary (record, policy, reports and the DMARCbis line), then the Tags table, which explains every tag in your record, and the RFC 9989 review below it.
- No record yet? Build one with the DMARC record generator, publish it, and run the check again.
The tool checks the exact name you enter. For a subdomain such as news.example.com without its own record, receivers fall back to the policy of the organizational domain (its sp= or np= value, otherwise p=). Check example.com as well before concluding that a subdomain is unprotected.
How to read the results
| Field | What it means |
|---|---|
| DMARC record | The full record as published. “Not found at _dmarc.example.com” (red) means receivers apply no DMARC policy, and Gmail, Yahoo and Outlook.com reject or filter bulk mail from the domain. |
| Records | Shown only when there is more than one DMARC record. Receivers then discard all of them, so the domain effectively has none. |
| Policy (p) | reject and quarantine are green, none is amber because it only monitors. “missing” means there is no p tag. |
| Percentage (pct) | Shown only when pct is set to something other than 100: the share of failing mail the policy is applied to under RFC 7489. |
| Aggregate reports (rua) | Where daily aggregate reports go. Amber when missing, because without reports you cannot see who sends mail as your domain. |
| DMARCbis (RFC 9989) | Green when the record uses no tags that RFC 9989 removed; amber when it still contains pct, rf or ri. |
| Tags table | Each tag in the record with its value and a plain explanation. |
| DMARCbis review | Notes on np, psd and t under RFC 9989, and on removed tags. An “info” row for np means it is not set and non-existent subdomains inherit sp or p. |
When you look at a received message, the DMARC result appears in the Authentication-Results header as dmarc=pass or dmarc=fail, together with header.from=, the domain that was evaluated. Gmail also prints the published policy in brackets, for example (p=REJECT sp=REJECT dis=NONE), where dis is what it actually did with the message.
Common problems and how to fix them
“Not found” although a record was added
Check that the record is at _dmarc.example.com and not on the domain itself, and that the panel did not turn it into _dmarc.example.com.example.com because you entered the full name. In cPanel Zone Editor, Cloudflare and most panels, the host field is just _dmarc. The value must start with v=DMARC1; a record beginning with p= is ignored.
dig +short TXT _dmarc.example.com
# Windows
nslookup -type=txt _dmarc.example.com 1.1.1.1
Two DMARC records
Often one from a hosting panel and one from a DMARC reporting service. RFC 9989 is explicit that receivers discard all of them, so the domain ends up with no policy. Keep one record and merge the rua addresses into it, separated by a comma: rua=mailto:dmarc@example.com,mailto:reports@example.net.
Gmail: “Unauthenticated email from example.com is not accepted due to domain’s DMARC policy”
This 550 5.7.26 bounce means the message failed DMARC and your published policy told Gmail to reject it. The sender is legitimate but neither SPF nor DKIM passed with a domain aligned to the From address. Find which service sent it in the aggregate reports, then set up custom-domain DKIM for that service or add it to SPF with a Return-Path on your domain.
Outlook.com: “550 5.7.515 Access denied, sending domain example.com does not meet the required authentication level”
Since May 2025 Microsoft requires domains sending 5,000 or more messages to its consumer mailboxes to pass SPF and DKIM, publish DMARC (at least p=none) and align at least one of SPF or DKIM with the From domain. Publish the record, then check SPF with the SPF checker and DKIM with the DKIM checker.
No aggregate reports arrive
First confirm the rua tag is present and starts with mailto:. If the address is on another domain, that domain must publish an authorisation record, or receivers will not send reports there: example.com._report._dmarc.example.net TXT v=DMARC1. Also check that the mailbox accepts large messages with zip or gzip attachments, and allow a day or two, because receivers send aggregate reports roughly once per day. The DMARC report analyzer turns the XML into a readable table.
Reports show your own services failing
A CRM, helpdesk or newsletter tool that sends with your From address but its own Return-Path and its own DKIM domain passes SPF and DKIM for its domain, not yours, so DMARC fails. Configure a custom return-path or bounce domain and custom DKIM at that provider before you move beyond p=none. Failures that come from forwarders and mailing lists are expected; those usually still pass DKIM when the message is not modified.
Who requires DMARC today
| Receiver | Requirement for bulk senders |
|---|---|
| Gmail | From February 2024, senders of more than 5,000 messages a day to Gmail must publish DMARC (p=none is enough) and pass SPF or DKIM aligned with the From domain. All senders need SPF or DKIM. See the Gmail and Yahoo checklist. |
| Yahoo | Similar rules for bulk senders, introduced at the same time as Gmail. |
| Outlook.com, Hotmail, Live | From May 2025, 5,000+ messages a day: SPF and DKIM must pass, DMARC at least p=none, and SPF or DKIM aligned with the From domain. Failing mail is rejected with 550 5.7.515. |
RFC 9989, published in May 2026, replaces RFC 7489 as the DMARC standard. Existing records keep working; the main edits are replacing pct with t=y while testing and adding np=reject. The changes are explained in DMARCbis (RFC 9989): what changed.
Official documentation: RFC 7489 (DMARC), DirectAdmin documentation, cPanel & WHM documentation.
Related guides: Warm up a new mail server IP or sending domain without landing in spam · Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin · Email forwarders with MailBaby: SRS, strict forwarding errors and backoffs.
Frequently asked questions
Is p=none enough?
It satisfies the Gmail and Yahoo bulk-sender requirement, but it does not stop spoofing. Plan to move to quarantine or reject.
What is DMARC alignment?
The domain in the visible From address must match the domain that passed SPF (the Return-Path) or the d= domain of a passing DKIM signature. Relaxed alignment accepts subdomains; strict needs an exact match.
Where do DMARC reports go?
To the mailto addresses in rua (daily aggregate XML) and ruf (forensic samples, rarely sent now). Use a dedicated mailbox or a report-processing service; reports can be large.
Does a subdomain need its own DMARC record?
Not usually. A subdomain without a record is covered by the organizational domain’s sp= policy, or p= when sp is absent. Publish a separate record only when a subdomain needs a different policy or report address.
What happens if the DMARC record has no p tag?
Under RFC 9989 an otherwise valid record without p is treated as p=none, so it monitors but does not protect. The checker shows the policy as “missing”.
Is the pct tag still supported?
RFC 9989 removed pct. Receivers that only implement the new standard apply the policy to all failing mail, so use t=y for a testing phase instead and remove pct.
Why do my reports show failures from IP addresses I do not know?
They are either spoofers using your domain, which DMARC is meant to stop, or forwarders and mailing lists relaying your real mail. Check the DKIM result in those rows: forwarded mail often still passes DKIM.
How long does a DMARC change take to apply?
Receivers use the new record once their cached copy expires, which is the TTL of the _dmarc TXT record. With a 3600-second TTL that is at most an hour.
Can DMARC reports go to more than one address?
Yes. List several mailto URIs in rua separated by commas. Addresses on other domains need an authorisation record at that domain.