Choose a policy and a reporting address to get a DMARC record ready to publish at _dmarc.yourdomain. The generator runs in your browser.
Table of Contents
A safe rollout
Publish p=none with a reporting address first. After two to four weeks of reports, fix any legitimate sender that fails, move to p=quarantine (optionally with pct to phase it in), and finally p=reject. Leave alignment relaxed unless you have a reason to be strict.
Verify with the DMARC checker after publishing.
DMARC record generator at a glance



How to use this tool
- Enter your domain, for example
example.com. The record is built for that exact name. - Choose the policy (
p): none to monitor, quarantine to send failing mail to spam, reject to refuse it. Start with none unless you have already checked every service that sends as your domain. - Enter an aggregate report address (
rua). You can type it with or withoutmailto:; the tool adds the prefix. Each field takes one address. - Optionally fill in the advanced fields: a failure report address (ruf) and when to send failure reports (fo), a percentage (pct), the subdomain policy (sp), the policy for non-existent subdomains (np), testing mode (t), and strict DKIM or SPF alignment.
- Press Generate DMARC. The result shows the host name, the record type and the value, each ready to copy into your DNS panel. Nothing is sent to our server; the record is built in your browser.
- After publishing, run the DMARC checker to confirm that receivers see exactly one valid record.
What each option adds to the record
| Field | Tag written | Notes |
|---|---|---|
| Policy | p=none, p=quarantine or p=reject | Always included, right after v=DMARC1. |
| Subdomain policy | sp= | Only added when you pick a value; otherwise subdomains follow p. |
| Non-existent subdomains | np= | RFC 9989 tag for names that do not exist in DNS. Only added when chosen; otherwise sp (or p) applies. |
| Testing mode | t=y | Asks receivers to apply one level less: reject is handled as quarantine, quarantine as none. |
| Apply to % of mail | pct= | Digits only; left out when empty or 100. RFC 9989 removed pct, so prefer testing mode. |
| Aggregate report address | rua=mailto: | Daily XML summaries of who sent mail as your domain and whether it passed. |
| Failure report address | ruf=mailto: | Per-message failure reports. Few large providers send them. |
| Send failure reports when | fo=1, fo=d or fo=s | Only added together with ruf. The default (0) reports when both SPF and DKIM fail; 1 when either fails; d when DKIM fails; s when SPF fails. |
| DKIM / SPF alignment | adkim=s / aspf=s | Only added when set to strict. Relaxed is the default and is left out. |
Below the record the generator adds notes that apply to your choices: a reminder to roll out in stages, a warning when pct is used, and, when a report address is on another domain, the exact authorisation record that domain must publish.
Example records for common situations
| Situation | Record value at _dmarc.example.com |
|---|---|
| Start: monitor only | v=DMARC1; p=none; rua=mailto:dmarc@example.com |
| Testing enforcement | v=DMARC1; p=quarantine; t=y; rua=mailto:dmarc@example.com |
| Quarantine everything that fails | v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com |
| Full protection | v=DMARC1; p=reject; rua=mailto:dmarc@example.com |
| Still monitoring, but stop made-up subdomains | v=DMARC1; p=none; np=reject; rua=mailto:dmarc@example.com |
| Domain that never sends mail | v=DMARC1; p=reject together with SPF v=spf1 -all and a null MX 0 . |
Keep alignment relaxed unless you know you need strict. With strict alignment, mail signed by d=mail.example.com or sent with a Return-Path on bounce.example.com no longer aligns with a From address on example.com, which breaks many sending platforms.
Publishing the record
- Type: TXT. Host or name: _dmarc. Value: the generated record, without extra spaces at the start.
- cPanel Zone Editor, DirectAdmin DNS Management, Plesk DNS Settings and Cloudflare all append the domain to the host. If your panel shows the full name, check that the result is
_dmarc.example.com, not_dmarc.example.com.example.com. - Some panels add the surrounding quotes themselves, others expect you to type them. Never paste text copied from a word processor; curly quotes break the record.
- Delete any older DMARC record at the same name first. Two records make receivers ignore both.
- A TTL of 3600 seconds is fine. Lower it to 300 during the weeks you are tightening the policy, so changes apply quickly.
Common problems and how to fix them
“Enter your domain.”
The domain field is empty. Enter the bare domain such as example.com, without https:// or _dmarc..
“The aggregate report address does not look like an email address.”
The rua field must contain one plain address such as dmarc@example.com. Commas, spaces and semicolons are rejected. To send reports to two places, generate the record with one address and add the second by hand: rua=mailto:dmarc@example.com,mailto:reports@example.net. The same check applies to the failure report address.
The record is published but the checker finds nothing
Usually a doubled host name or a record saved in a DNS zone that is not authoritative for the domain (for example in cPanel while the domain uses Cloudflare). Look up _dmarc.example.com with the DNS lookup using the authoritative name server.
Reports go to an external service but never arrive
The receiving domain must publish an authorisation record such as example.com._report._dmarc.example.net TXT v=DMARC1. Reporting services normally publish this for you, sometimes with a wildcard; if you send reports to your own second domain, publish it yourself. The generator prints the exact name.
Legitimate mail is rejected after switching to p=reject
A sender passed SPF or DKIM only for its own domain, not yours. Go back to p=quarantine; t=y or p=none, find the failing source in the aggregate reports with the DMARC report analyzer, set up custom-domain DKIM or a custom return-path for it, and tighten the policy again.
Official documentation: RFC 7489 (DMARC), DirectAdmin documentation, cPanel & WHM documentation.
Related guides: Warm up a new mail server IP or sending domain without landing in spam · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback · Whitelisting MailBaby in cPanel greylisting, CSF and SpamAssassin.
Frequently asked questions
Where do I add the record?
As a TXT record with host _dmarc (so the full name is _dmarc.example.com).
Can reports go to another domain?
Yes, but that domain must publish example.com._report._dmarc.otherdomain TXT “v=DMARC1” to accept them — the generator shows the exact name.
Should I use ruf forensic reports?
Few providers send them any more and they can contain personal data; aggregate rua reports are enough for most domains.
Can I add more than one rua address?
Yes, as a comma-separated list of mailto addresses. The generator takes one address per field, so add further addresses to the generated value by hand.
Why is fo not in my record?
The generator only adds fo when you also enter a failure report (ruf) address, because fo only controls when failure reports are sent.
What does np=reject do?
It applies reject to mail from subdomains that do not exist in DNS, such as random.example.com. It stops that kind of spoofing even while p is still none.
Is t=y the same as pct=0?
They serve the same purpose. Under RFC 9989, t=y asks receivers to apply one policy level lower, and it replaces the old habit of using pct=0 or a low pct as a test switch.
Should I use strict alignment?
Usually not. Relaxed alignment accepts subdomains of your domain, which most sending platforms rely on. Strict only makes sense when every sender uses exactly the From domain.
Does the generator send my domain or addresses anywhere?
No. The record is assembled in your browser and nothing is sent to our server.