Free Tool · Email Authentication

DMARC Record Builder

DMARC is what tells the world what to do with mail that fails your SPF and DKIM checks — and it’s how you finally see who’s sending as your domain. Build a correct record with safe defaults, and follow the ramp so you never accidentally block your own mail.

🔒 Everything runs in your browser. Looking up an existing record uses Cloudflare’s DNS-over-HTTPS; nothing you type is sent to ThouShaltNotClick.

Build your DMARC record

p=none
Monitor 4–6 weeks
p=quarantine
pct=10 → ramp up
p=reject
Full enforcement
Policy for mail that fails DMARC
Use a mailbox or a DMARC report service — NOT the principal’s inbox (reports are XML).
Can carry pieces of real message content — leave blank unless you have a reason.
Alignment mode — advanced; relaxed is right for almost everyone.
TXT record at _dmarc.yourdomain.org
v=DMARC1; p=none
Medium: No rua (aggregate report) address. DMARC reports are how you discover which senders would be affected before you enforce — add one, even at p=none.
How to publish: add a TXT record with the host/name _dmarc (many DNS panels want just _dmarc) and the value above. DMARC needs SPF or DKIM to already be aligned for your legitimate mail — build your SPF record first if you haven’t. Give changes up to 48 hours to propagate.
← Check or build your SPF record
DMARC leans on SPF/DKIM alignment. Get SPF right first.
Is my domain spoofable? →
A 0–100 risk score across SPF, DMARC, and DKIM.
DMARC stops the spoof. Training stops the click.
See how ThouShaltNotClick protects the whole school.
See how it works →