DMARC Record Checker
Instantly check any domain's DMARC record, policy strength, and reporting setup.
Need to monitor this across every client domain you manage? ActiScan does bulk scanning, scoring, and white-labeled reporting for MSPs.
How to Use the DMARC Checker
Enter a domain
No http:// prefix – just the domain itself (e.g. company.com).
Click Check
ActiScan looks up the domain's _dmarc TXT record live, over DNS.
Read the result
A pass/warn/fail status plus a plain-English explanation of what to do next.
What Your Result Means
p=rejectPassThe strongest policy: mail that fails DMARC is blocked outright, not just flagged. If rua= is also set, you're getting aggregate reports on top of full enforcement – this is the end state to aim for.
p=quarantine or p=noneWarnA record exists, but it isn't fully protecting you yet. p=quarantine sends failing mail to spam; p=none only monitors and takes no action at all – attackers can still spoof you undetected. Both are meant as a transition step, not a destination.
No record foundFailThe domain publishes no DMARC policy. Anyone can send mail that appears to come from it, with no authentication check on the receiving end.
What is a DMARC Record?
A DMARC record is a DNS TXT record that tells receiving mail servers how to handle email that fails authentication. It builds on SPF and DKIM by adding a policy – monitor, quarantine, or reject – and a place to send reports on what's happening.
It's published at the _dmarc subdomain: for example.com, that's _dmarc.example.com. When mail claiming to be from your domain arrives somewhere, the receiving server checks SPF and DKIM, verifies alignment, reads your DMARC record, and applies whatever policy you've published.
DMARC Record Examples
Monitoring only
v=DMARC1; p=none; rua=mailto:dmarc@example.com;
Collects aggregate reports without affecting delivery – the usual starting point before enforcing anything.
Partial enforcement
v=DMARC1; p=quarantine; pct=50; rua=mailto:dmarc@example.com;
Quarantines half of failing mail (pct=50), letting you ramp up enforcement gradually instead of all at once.
Full enforcement
v=DMARC1; p=reject; rua=mailto:dmarc@example.com; adkim=s; aspf=s;
Rejects unauthenticated mail outright, with strict SPF/DKIM alignment and reporting – the strongest configuration.
Need to build your own? Use the free DMARC generator.
DMARC Record Tags Explained
| Tag | What it does | Example | Required? |
|---|---|---|---|
| v | Protocol version. Must be the first tag. | v=DMARC1 | Required |
| p | Policy for the domain itself. | p=reject | Required |
| rua | Address(es) for aggregate (summary) reports. | rua=mailto:dmarc@example.com | Optional (recommended) |
| ruf | Address(es) for forensic (per-message failure) reports. | ruf=mailto:forensics@example.com | Optional |
| sp | Policy for subdomains. Falls back to p= if omitted. | sp=quarantine | Optional |
| pct | Percentage of failing mail the policy applies to. | pct=50 | Optional |
| adkim | DKIM alignment mode: s (strict) or r (relaxed). | adkim=s | Optional |
| aspf | SPF alignment mode: s (strict) or r (relaxed). | aspf=s | Optional |
How to Find Your DMARC Record Manually
If you'd rather look it up yourself instead of using the checker above:
Using nslookup
nslookup -type=TXT _dmarc.yourdomain.com
Using dig
dig TXT _dmarc.yourdomain.com
Next Steps After Your Check
At p=none? Move toward enforcement.
ActiScan tracks your policy over time and flags when you're ready to tighten it.
Start free trial →Want ongoing monitoring?
ActiScan scans on a schedule and alerts you when something changes – across every domain you manage.
Start free trial →Frequently Asked Questions
Is this DMARC checker free?
Yes – check any domain's DMARC record for free, no signup required.
Do I need to own the domain I'm checking?
No. DMARC records are published in public DNS, so anyone can look one up.
Why does my domain show "no record" right after I added one?
DNS changes take time to propagate – wait for the record's TTL to expire (often up to a few hours) and check again.
What's the difference between a valid record and an enforced one?
Valid just means correctly formatted. If the policy is p=none, it's valid but not enforcing – it monitors without blocking spoofed mail. Enforcement means p=quarantine or p=reject.
Where is a DMARC record stored?
As a TXT record at the _dmarc subdomain – for example.com, that's _dmarc.example.com.