DMARC Checker
A DMARC checker reads your domain's DMARC policy — the DNS TXT record at _dmarc.yourdomain that tells inbox providers what to do when SPF or DKIM fail. This free tool shows whether DMARC exists and whether your policy (none, quarantine, or reject) is actually enforcing.
Policy strength · Gmail/Yahoo 2024 sender requirements
Frequently asked questions
What is a DMARC record?
DMARC is a DNS TXT record at _dmarc.yourdomain that tells receiving servers what to do when a message fails SPF and DKIM alignment — and where to send aggregate reports. It is what actually turns email authentication into spoofing protection.
What is the difference between p=none, p=quarantine and p=reject?
p=none only monitors — failing mail is still delivered. p=quarantine sends failures to spam. p=reject blocks them outright. none is a safe starting point for collecting reports, but only quarantine or reject actually stop spoofing, so treat none as a temporary state.
Is p=none good enough?
No, not as a destination. p=none gives you visibility via reports but provides zero enforcement — anyone can still spoof your From address. Move to quarantine, then reject, once your reports show legitimate senders pass.
Do I need SPF and DKIM for DMARC to work?
Yes. DMARC evaluates SPF and DKIM results and requires that at least one passes and aligns with your From domain. Set up SPF and DKIM first, confirm they pass, then publish and tighten DMARC.
Gmail and Yahoo require DMARC — what do I need?
As of 2024, bulk senders to Gmail and Yahoo must publish a valid DMARC record (at least p=none), pass SPF or DKIM with alignment, and honour one-click unsubscribe. This tool confirms your DMARC record exists and reports its policy strength.