Free DMARC Record Generator
Answer a few questions and get a valid DMARC TXT record to publish at _dmarc.yourdomain.com.
How to Use the Generator
Choose a policy
Start with none while you confirm reporting is flowing, then tighten to quarantine or reject.
Set your reporting addresses
Enter where aggregate (rua) reports – and optionally forensic (ruf) reports – should be sent.
Generate and publish
Copy the record into a TXT record at _dmarc.yourdomain.com in your DNS provider.
What Each Field Means
| Field | What it does | Example |
|---|---|---|
| Policy (p) | What receivers do with mail that fails DMARC: none delivers it as normal, quarantine sends it to spam, reject refuses it. Always present – required by the spec. | p=reject |
| Subdomain policy (sp) | Overrides the policy specifically for subdomains. Left as "same as policy above," this tag is omitted and receivers fall back to p=. | sp=quarantine |
| Aggregate reports (rua) | Comma-separated email address(es) that receive periodic XML summary reports of pass/fail volumes across all senders. | rua=mailto:dmarc@example.com |
| Forensic reports (ruf) | Comma-separated email address(es) that receive per-message failure reports. Optional, and only a subset of receivers honor it. | ruf=mailto:forensics@example.com |
Example Outputs
Monitoring only
v=DMARC1; p=none; rua=mailto:dmarc@example.com
Policy set to none, rua filled in – collects reports without affecting delivery. The usual starting point.
Stricter subdomains
v=DMARC1; p=quarantine; sp=reject; rua=mailto:dmarc@example.com
Subdomain policy set to reject while the main domain quarantines – useful when subdomains never send legitimate mail.
Full enforcement with forensics
v=DMARC1; p=reject; rua=mailto:dmarc@example.com; ruf=mailto:forensics@example.com
Policy set to reject with both rua and ruf filled in – the strongest configuration this generator can produce.
Next Steps
Verify what you just generated
After you publish the record, confirm it resolves correctly and check its policy strength.
DMARC Checker →DMARC needs SPF and DKIM too
DMARC only evaluates mail that already has an aligned, passing SPF or DKIM result – make sure both are set up.
SPF Generator →Managing multiple client domains?
ActiScan tracks policy strength over time and flags when a client is ready to move from none toward enforcement.
Start free →Frequently Asked Questions
Is this DMARC generator free?
Yes – build and download as many DMARC records as you need, no signup required.
Where do I publish the record it gives me?
As a TXT record at the _dmarc subdomain – for example.com, that's _dmarc.example.com, not the domain root.
Should I start with p=none?
Yes, if you haven't run DMARC before. It lets you collect aggregate reports and confirm SPF/DKIM are aligned for every legitimate sender before you risk blocking real mail with quarantine or reject.
Do I need a rua address?
It's optional but strongly recommended – without it you're publishing a policy blind, with no visibility into what's passing or failing.
What about pct, adkim, and aspf tags?
This generator covers the fields most domains need to get started. The full DMARC spec also supports pct= (percentage of mail a policy applies to) and adkim=/aspf= (strict vs. relaxed alignment) – see the complete tag reference on the DMARC checker page.