ActiScan

DMARC Record Checker

Instantly check any domain's DMARC record, policy strength, and reporting setup.

Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.

How to Use the DMARC Checker

1

Enter a domain

No http:// prefix – just the domain itself (e.g. company.com).

2

Click Check

ActiScan looks up the domain's _dmarc TXT record live, over DNS.

3

Read the result

A pass/warn/fail status plus a plain-English explanation of what to do next.

What Your Result Means

p=rejectPass

The strongest policy: mail that fails DMARC is blocked outright, not just flagged. If rua= is also set, you're getting aggregate reports on top of full enforcement – this is the end state to aim for.

p=quarantine or p=noneWarn

A record exists, but it isn't fully protecting you yet. p=quarantine sends failing mail to spam; p=none only monitors and takes no action at all – attackers can still spoof you undetected. Both are meant as a transition step, not a destination.

No record foundFail

The domain publishes no DMARC policy. Anyone can send mail that appears to come from it, with no authentication check on the receiving end.

What is a DMARC Record?

A DMARC record is a DNS TXT record that tells receiving mail servers how to handle email that fails authentication. It builds on SPF and DKIM by adding a policy – monitor, quarantine, or reject – and a place to send reports on what's happening.

It's published at the _dmarc subdomain: for example.com, that's _dmarc.example.com. When mail claiming to be from your domain arrives somewhere, the receiving server checks SPF and DKIM, verifies alignment, reads your DMARC record, and applies whatever policy you've published.

DMARC Record Examples

Monitoring only

v=DMARC1; p=none; rua=mailto:dmarc@example.com;

Collects aggregate reports without affecting delivery – the usual starting point before enforcing anything.

Partial enforcement

v=DMARC1; p=quarantine; pct=50; rua=mailto:dmarc@example.com;

Quarantines half of failing mail (pct=50), letting you ramp up enforcement gradually instead of all at once.

Full enforcement

v=DMARC1; p=reject; rua=mailto:dmarc@example.com; adkim=s; aspf=s;

Rejects unauthenticated mail outright, with strict SPF/DKIM alignment and reporting – the strongest configuration.

Need to build your own? Use the free DMARC generator.

DMARC Record Tags Explained

TagWhat it doesExampleRequired?
vProtocol version. Must be the first tag.v=DMARC1Required
pPolicy for the domain itself.p=rejectRequired
ruaAddress(es) for aggregate (summary) reports.rua=mailto:dmarc@example.comOptional (recommended)
rufAddress(es) for forensic (per-message failure) reports.ruf=mailto:forensics@example.comOptional
spPolicy for subdomains. Falls back to p= if omitted.sp=quarantineOptional
pctPercentage of failing mail the policy applies to.pct=50Optional
adkimDKIM alignment mode: s (strict) or r (relaxed).adkim=sOptional
aspfSPF alignment mode: s (strict) or r (relaxed).aspf=sOptional

How to Find Your DMARC Record Manually

If you'd rather look it up yourself instead of using the checker above:

Using nslookup

nslookup -type=TXT _dmarc.yourdomain.com

Using dig

dig TXT _dmarc.yourdomain.com

Next Steps After Your Check

No record found?

Build a valid one in under a minute, no manual editing required.

DMARC Generator →

At p=none? Move toward enforcement.

ActiScan tracks your policy over time and flags when you're ready to tighten it.

Start free trial →

Want ongoing monitoring?

ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.

Start free trial →

Frequently Asked Questions

Is this DMARC checker free?

Yes – check any domain's DMARC record for free, no signup required.

Do I need to own the domain I'm checking?

No. DMARC records are published in public DNS, so anyone can look one up.

Why does my domain show "no record" right after I added one?

DNS changes take time to propagate – wait for the record's TTL to expire (often up to a few hours) and check again.

What's the difference between a valid record and an enforced one?

Valid just means correctly formatted. If the policy is p=none, it's valid but not enforcing – it monitors without blocking spoofed mail. Enforcement means p=quarantine or p=reject.

Where is a DMARC record stored?

As a TXT record at the _dmarc subdomain – for example.com, that's _dmarc.example.com.

Use the free DMARC checker as often as you need

Start free trial