Skip to main content

Free tools

DMARC checker — validate policy, reporting & alignment

Enter your organizational sending domain to check the DMARC TXT record at _dmarc, policy mode (none/quarantine/reject), aggregate reporting addresses, and alignment settings.

Back to content tools

At a glance

What it is
DNS-based DMARC validator with policy analysis, rua/ruf reporting checks, alignment tags, and SPF readiness hints.
Who it is for
Email marketers, deliverability leads, and MailFleet users tightening authentication policy.
Main capabilities
Policy meter, reporting addresses, tag table, pct rollout, alignment, SPF hint, captcha, rate limits.
Platforms
Browser-based diagnostic on mailfleet.app with server-side DNS checks when the live service is available.
Responsible use
Validates DNS publication only. Process aggregate XML reports separately for full visibility.

DMARC DNS validation

Query _dmarc.domain, validate policy, reporting, and alignment tags.

p=none — Monitor onlyp=quarantine — Junk/quarantine failuresp=reject — Reject failures

Organizational domain

Security verification

Required to prevent automated abuse of the public DNS checker.

Verification challenge

Capabilities

Validate DMARC before you enforce

Catch missing records, bad reporting addresses, and premature p=reject before they affect deliverability.

  • _dmarc DNS lookup

    Queries the exact host receivers use — _dmarc.yourdomain.com.

  • Policy analysis

    Validates p=none, quarantine, or reject and optional subdomain sp= policy.

  • Reporting addresses

    Parses rua aggregate and ruf forensic mailto destinations.

  • Alignment tags

    Shows adkim and aspf relaxed (r) vs strict (s) alignment settings.

  • Rollout & pct

    Flags partial pct rollout and warns before p=reject without SPF/DKIM readiness.

  • Abuse-resistant

    Image captcha, session verification, and per-IP rate limits for public use.

How to use

Five steps to a solid DMARC policy

  1. 1

    Enter org domain

    Use the domain in your From address — the organizational domain that publishes DMARC.

  2. 2

    Solve captcha

    Complete the image challenge before querying DNS.

  3. 3

    Review policy

    Check p= mode and whether sp= differs for subdomains.

  4. 4

    Verify reporting

    Confirm rua= points to a monitored mailbox or DMARC vendor.

  5. 5

    Tighten gradually

    Move from none → quarantine → reject after SPF/DKIM pass consistently.

What is DMARC?

Domain-based Message Authentication, Reporting and Conformance (DMARC) builds on SPF and DKIM. It tells receivers what to do when authentication fails and where to send aggregate reports about your mail.

DMARC is published as a TXT record at _dmarc.yourdomain. Policy tag p= controls enforcement: none (monitor), quarantine, or reject.

Recommended policy rollout

Most teams start with p=none and rua= reporting to collect data. After SPF and DKIM align consistently, move to quarantine, then reject.

Publishing p=reject before authentication is fixed can block legitimate mail from new providers or subdomains.

  • p=none — monitoring phase, no enforcement
  • p=quarantine — failed mail may land in spam
  • p=reject — failed mail should be rejected outright
  • rua=mailto:… — required for useful aggregate reports

What this tool does not do

This checker validates DNS publication and DMARC syntax. It does not process DMARC XML reports or prove inbox placement.

SPF hint is a quick presence check only — validate full SPF and DKIM with the dedicated tools.

Key takeaways

  • DMARC lives at _dmarc.yourdomain — not the apex domain.
  • Start with p=none and rua= reporting before enforcing quarantine or reject.
  • adkim/aspf control relaxed vs strict alignment with your From domain.
  • Validate SPF and DKIM alongside DMARC for full authentication.

For regulatory context on commercial email in the United States, see the FTC CAN-SPAM compliance guide.

Delivery note: MailFleet helps users manage campaigns through their own sending providers. Delivery outcomes depend on sender reputation, DNS authentication, content quality, recipient engagement, list quality, provider rules, and mailbox filtering systems.

DMARC checker FAQ

Yes. p=none lets you collect rua reports without enforcing failures. Fix SPF/DKIM issues, then tighten policy.

Get started

Tighten authentication with MailFleet

Campaign logs, provider profiles, and pre-send checks help you move DMARC policy safely.

Available on

  • Windows 10+
  • macOS 12+
  • Linux (DEB & RPM)

Same desktop experience across every platform — one workflow for your entire team.