ActiScan

Free DMARC Record Generator

Answer a few questions and get a valid DMARC TXT record to publish at _dmarc.yourdomain.com.

Which policy should I choose?
p=none None
Mail that fails DMARC is delivered as normal. Nothing is blocked, and reports show who is sending as the domain.Where every domain starts, until the reports show every real sender passing.
p=quarantine Quarantine
Mail that fails DMARC goes to the recipient's spam or junk folder instead of the inbox.The middle step, once every real sender passes. It can start on a share of failing mail (pct=25) to be careful.
p=reject Reject
Mail that fails DMARC is refused and never delivered.Full protection against spoofing, once quarantine has run without real mail failing. BIMI logos require it.

How to Use the Generator

1

Choose a policy

Start with none while you confirm reporting is flowing, then tighten to quarantine or reject.

2

Set your reporting addresses

Enter where aggregate (rua) reports – and optionally forensic (ruf) reports – should be sent.

3

Generate and publish

Copy the record into a TXT record at _dmarc.yourdomain.com in your DNS provider.

What Each Field Means

FieldWhat it doesExample
Policy (p)What receivers do with mail that fails DMARC: none delivers it as normal, quarantine sends it to spam, reject refuses it. Always present – required by the spec.p=reject
Subdomain policy (sp)Overrides the policy specifically for subdomains. Left as "same as policy above," this tag is omitted and receivers fall back to p=.sp=quarantine
Aggregate reports (rua)Comma-separated email address(es) that receive periodic XML summary reports of pass/fail volumes across all senders.rua=mailto:dmarc@example.com
Forensic reports (ruf)Comma-separated email address(es) that receive per-message failure reports. Optional, and only a subset of receivers honor it.ruf=mailto:forensics@example.com

Example Outputs

Monitoring only

v=DMARC1; p=none; rua=mailto:dmarc@example.com

Policy set to none, rua filled in – collects reports without affecting delivery. The usual starting point.

Stricter subdomains

v=DMARC1; p=quarantine; sp=reject; rua=mailto:dmarc@example.com

Subdomain policy set to reject while the main domain quarantines – useful when subdomains never send legitimate mail.

Full enforcement with forensics

v=DMARC1; p=reject; rua=mailto:dmarc@example.com; ruf=mailto:forensics@example.com

Policy set to reject with both rua and ruf filled in – the strongest configuration this generator can produce.

Next Steps

Verify what you just generated

After you publish the record, confirm it resolves correctly and check its policy strength.

DMARC Checker →

DMARC needs SPF and DKIM too

DMARC only evaluates mail that already has an aligned, passing SPF or DKIM result – make sure both are set up.

SPF Generator →

Managing multiple client domains?

ActiScan tracks policy strength over time and flags when a client is ready to move from none toward enforcement.

Start free →

Frequently Asked Questions

Is this DMARC generator free?

Yes – build and download as many DMARC records as you need, no signup required.

Where do I publish the record it gives me?

As a TXT record at the _dmarc subdomain – for example.com, that's _dmarc.example.com, not the domain root.

Should I start with p=none?

Yes, if you haven't run DMARC before. It lets you collect aggregate reports and confirm SPF/DKIM are aligned for every legitimate sender before you risk blocking real mail with quarantine or reject.

Do I need a rua address?

It's optional but strongly recommended – without it you're publishing a policy blind, with no visibility into what's passing or failing.

What about pct, adkim, and aspf tags?

This generator covers the fields most domains need to get started. The full DMARC spec also supports pct= (percentage of mail a policy applies to) and adkim=/aspf= (strict vs. relaxed alignment) – see the complete tag reference on the DMARC checker page.

Generate and check DMARC records as often as you need

Start free trial