Tools

Your DMARC record,
and the one to publish next.

Read what a domain publishes today, then build the record that moves it forward. Every tag explained, nothing invented, and a warning wherever a choice would quietly break real mail.

Build the record

Policy

Receivers change nothing and just send you reports. Forged mail still arrives. This is a measuring position, not a protection.

Subdomain policy

Left to inherit, subdomains follow the policy above. Set it weaker and mail.yourdomain.com becomes the way in.

A daily XML summary of everything sent in your name. Any mailbox on your own domain will do; separate several addresses with commas.

Copies of individual failures. Most receivers never send them, and those that do may include message content. Leave it empty unless you know you want it.

DKIM alignment

Relaxed lets a subdomain sign. Strict demands the exact domain.

SPF alignment

Strict here is what breaks most third-party senders.

The record to publish
TypeTXT
Name_dmarc
Valuev=DMARC1; p=none;

Most registrars want _dmarc alone in the name field and append the domain for you. A few want the whole thing. If you end up with a record at _dmarc.yourdomain.com.yourdomain.com, that is which one yours is.

  • No aggregate report address. You will not find out what this policy breaks until somebody tells you their mail never arrived.
What to do after publishing

Publish this, then leave it alone for two to four weeks. The aggregate reports will name every service sending as your domain. Fix the ones failing that should not be, then come back and move to quarantine.

Every DMARC tag

v=
DMARC1
The version, and it must be the first tag in the record. A record that does not open with it is ignored.
p=
none · quarantine · reject
What receivers should do with mail that fails. The only required tag besides v.
sp=
none · quarantine · reject
The policy for subdomains. Left out, subdomains inherit p. Setting it weaker than p is how domains get forged through mail.acme.com.
pct=
0–100
The share of failing mail the policy is applied to. A ramp, not a setting. It does nothing at all with p=none.
rua=
mailto: address
Where daily aggregate reports go. Without it you are enforcing blind, so in practice it is required.
ruf=
mailto: address
Forensic reports on individual failures. They can carry message content, most receivers never send them, and almost nobody needs them.
adkim=
r · s
How closely the DKIM signing domain must match. Relaxed allows subdomains; strict demands the exact domain.
aspf=
r · s
The same question for SPF. Strict here breaks most third-party senders.
fo=
0 · 1 · d · s
When to generate a forensic report. Only meaningful alongside ruf.
ri=
seconds
How often aggregate reports are wanted. Almost everyone leaves this at the default of 86400 (one day).

Questions this raises

What is a DMARC record?

A TXT record at _dmarc.yourdomain.com that tells receiving mail servers what to do when a message claiming to be from you fails SPF and DKIM. SPF and DKIM decide whether a message authenticates; DMARC is the only part that says what should happen when it does not.

What does p=none actually do?

Nothing to the mail. It asks receivers to treat failing messages exactly as they would have anyway, and to send you a daily report of what they saw. That report is the point. It shows every service sending as your domain, including the ones nobody remembers setting up. p=none is where you start and it is not where you stop.

Where do I put the DMARC record?

As a TXT record on the host _dmarc. Most registrars want just _dmarc in the name field and add your domain automatically; a few want the full _dmarc.yourdomain.com. If you end up with a record at _dmarc.yourdomain.com.yourdomain.com, that is the one to fix.

Should I go straight to p=reject?

Only if you already know every system that sends as your domain, and almost nobody does. Invoicing tools, help desks, marketing platforms and recruiting software all send as you and are all easy to forget. Run p=none with a rua address for two to four weeks, read the reports, fix what fails, then move up.

Do I need a rua address?

In practice yes. Without it nothing reports back, so you have no way of knowing whether tightening the policy will break real mail. It can be an ordinary mailbox on your own domain. The reports arrive as compressed XML attachments, and any DMARC report reader will make them legible.

What does pct do?

It applies the policy to a percentage of failing mail and delivers the rest normally, so you can move to quarantine at 10% and watch what happens rather than at 100% and find out. It has no effect with p=none, and leaving it below 100 permanently means most forged mail is still getting through.

OpenEmail generates this record for you.

Add a domain and you get the exact MX, SPF and signing records to publish, checked from the settings screen until they resolve. The DMARC record is generated alongside them and deliberately left for you to publish. It is a policy about mail you send, and nobody should choose p=reject on your behalf.

Set up a domain

Your inbox, on your
own terms.

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

OpenEmail

Email infrastructure for businesses, AI, agents and personal email. Built for scale, privacy and control. Everything email should have had from day one.

© 2026 OpenEmail. All rights reserved.The all in one email tool.