Free tool
DMARC Record Generator
Enter a domain and get the DMARC record it should publish next — based on the SPF, DKIM and DMARC it already has, not on tags you have to choose yourself.
Go beyond this tool. Manage DNS across every provider — in one dashboard.
Get started free →DMARC builds on SPF and DKIM. It sets a policy (monitor, quarantine or reject) for messages that fail authentication, and can send you reports about who is sending mail as your domain. It is the key record for stopping spoofing and phishing.
This starts from your domain rather than from a blank form, because almost everything a DMARC record needs can be read from DNS. It checks whether SPF and DKIM are actually in place — a policy of quarantine or reject with neither underneath refuses your own mail — and recommends the one rung of the ladder you have earned, instead of offering three equal choices to someone who came here to find out which is right.
It also checks the reporting address, which is where this quietly goes wrong: a suggested dmarc@yourdomain that nobody ever created looks perfectly fine and delivers nothing, and a report address at another domain does nothing at all unless that domain has authorised yours. Both failures are silent, and an empty inbox looks exactly like having nothing to report.
Full email security in one click
InfraNest applies SPF, DKIM and DMARC together with its email-security template — no manual record juggling, across all your domains.
- One-click SPF + DKIM + DMARC
- Diff preview before apply
- Live sync to your provider
- Works across all your domains
Frequently asked questions
#What does DMARC actually do?
DMARC ties SPF and DKIM to the address your recipients see. It tells receiving servers what to do when a message fails both checks, and asks them to report back on who is sending mail as your domain.
#Where does the record go?
As a TXT record on _dmarc.yourdomain.com — not on the root domain, which is where SPF lives. Publishing DMARC on the root instead is the single most common reason a policy appears to do nothing.
#What is the difference between p=none, quarantine and reject?
none changes nothing and only collects reports. quarantine asks receivers to treat failing mail as suspicious, usually the spam folder. reject asks them to refuse it outright. Move through them in that order.
#What are rua and ruf?
rua is the address for aggregate reports — daily XML summaries of who sent mail as your domain and whether it passed. ruf is for per-message forensic reports, which most large providers no longer send for privacy reasons. rua is the one that matters.
#Why does it ask for my domain instead of just building a record?
Because the answer depends on what you already have. Whether quarantine is safe depends on SPF and DKIM being in place; whether reports will reach you depends on the mailbox existing and, for an address at another domain, on that domain authorising yours. A blank form cannot know any of that, so it hands the decision to the person least able to make it. If you would rather have the plain builder, there is a link to it under the domain box.
#How do you know whether DKIM is set up?
DKIM can only be looked up if you know the selector, so the check tries the ones the large providers document — google, selector1 and selector2, k1, and about fifteen more. Finding one proves DKIM is signing; finding none proves nothing except that it is not on a name we know to try, and the result says so rather than claiming DKIM is missing.
#Do I need SPF and DKIM first?
Yes. DMARC does not authenticate anything by itself — it checks whether an SPF or DKIM pass aligns with the visible From domain. Publish both first, watch the aggregate reports for a few weeks on p=none, then tighten the policy.
From the blog
More free tools
One lookup is a snapshot
InfraNest keeps checking — across every domain you own — and tells you when the answer changes instead of when a customer does.
Free plan · No credit card required · Set up in minutes