---
title: "Check the DMARC policy of a domain"
description: "What the DMARC record of any domain says, and what is wrong with it."
url: "https://openemail.uk/docs/api/tools/dmarc"
area: "API"
category: "Mailbox"
---

# Check the DMARC policy of a domain

What the DMARC record of any domain says, and what is wrong with it.

`GET /tools/dmarc`

## GET /tools/dmarc

What the DMARC record of any domain says, and what is wrong with it.

## Example

Needs no scope. `domain` is any public domain, and an email address or a URL is read as its domain. `stage` is `missing`, `invalid`, `monitor` for `p=none`, `quarantine` or `reject`.

**curl**

```
curl "$OE/tools/dmarc?domain=acme.com" -H "$AUTH"
```

**Response**

```
{
  "object": "dmarc_report",
  "domain": "acme.com",
  "record": "v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com",
  "inheritedFrom": null,
  "tags": { "v": "DMARC1", "p": "quarantine", "rua": "mailto:dmarc@acme.com" },
  "stage": "quarantine",
  "issues": []
}
```

> A subdomain with no record of its own inherits the record of its organisational domain, and `inheritedFrom` names it.

> Every answer is what public DNS said at that moment. DNS that does not answer is a 503 `unreachable`, which is worth retrying, and a value that does not read as a domain is a 422 `invalid_parameter` on `domain`.

## Reference

- [`GET /tools/dmarc`](https://openemail.uk/docs/api/reference/tools#get-tools-dmarc): full reference
