Free tool
DMARC Checker
Read a domain’s DMARC record and see what it really asks receivers to do — including whether reports are reaching you at all.
Go beyond this tool. Manage DNS across every provider — in one dashboard.
Get started free →DMARC is the record that decides what happens to mail that fails authentication, and the one that sends you reports about who is sending as your domain. Most published records are valid and inert: p=none asks receivers to do nothing, which is the right place to start and the wrong place to stay.
This check reads the policy in plain terms, flags the settings that quietly weaken it — a partial pct, subdomains exempted by sp=none — and confirms that an external reporting address has actually authorised your domain to send it reports. That last one fails silently: no error is raised anywhere, the reports simply never arrive, and the owner concludes nobody is forging them.
Email security, watched rather than remembered
InfraNest checks SPF, DKIM and DMARC on every domain you manage, and its email-security template writes all three with a diff preview before anything is applied.
- SPF, DKIM & DMARC checked on every zone
- One-click email-security template
- Diff preview before you apply
- Alerts when a record changes or breaks
Frequently asked questions
#What does p=none actually do?
Nothing, to the mail. It asks receivers to deliver as they normally would and to send you reports. That makes it the safe way to begin — you learn which of your own senders would fail before any of them do — but a domain left there is exactly as forgeable as one with no DMARC at all.
#How do I move from none to reject?
Collect aggregate reports for a few weeks and confirm every legitimate sender passes SPF or DKIM with alignment. Then move to p=quarantine, watch again, and finish at p=reject. The reports are what make each step safe, which is why a record with no rua= is hard to tighten.
#Why would DMARC reports never arrive?
Most often because the address is at another domain — a reporting service, or a colleague’s — and that domain has not published the authorisation record naming yours. Conforming receivers then send nothing at all. It produces no error, so it looks exactly like having no forgery to report.
#What is the difference between relaxed and strict alignment?
Relaxed lets a subdomain count as a match, so mail from mail.example.com can align with example.com. Strict requires the exact domain. Relaxed is the default and suits almost everyone; strict breaks many legitimate senders.
#Do I need SPF and DKIM as well?
Yes. DMARC authenticates nothing by itself — it checks whether an SPF or DKIM pass aligns with the visible From address. Publishing DMARC with neither underneath it means everything fails, which is why p=reject in that state can refuse your own mail.
#What does pct= do?
It applies the policy to only that share of failing mail; the rest is treated as one step weaker. It is useful while rolling out and easy to leave behind — and a forger only needs the untouched share.
From the blog
More free tools
One lookup is a snapshot
InfraNest keeps checking — across every domain you own — and tells you when the answer changes instead of when a customer does.
Free plan · No credit card required · Set up in minutes