Check your DMARC record

Enter a domain to look up its DMARC record, validate every tag, and see exactly what's blocking enforcement — free, no signup. A healthy record starts at v=DMARC1 and ends at p=reject.

What is a DMARC record?

A DMARC (Domain-based Message Authentication, Reporting, and Conformance) record is a DNS record that helps protect email domains from unauthorized use, such as spoofing. It does this by specifying how emails that fail SPF (Sender Policy Framework) and DKIM (DomainKeys Identified Mail) checks should be handled (e.g., rejected or quarantined). Additionally, DMARC provides feedback to domain owners about the emails being sent from their domain, helping them identify and address security issues.

How to read your result

ResultWhat it meansWhat to do
v=DMARC1; p=rejectFull enforcement request — participating receivers are asked to reject mail that fails DMARC.Keep rua reporting on and watch for new senders before you onboard them.
p=quarantineEnforcement request, softened: receivers are asked to treat failing mail as suspicious, often by placing it in spam.Watch reports for false positives for a few weeks, then move to p=reject.
p=noneMonitoring only — the domain requests reports but no enforcement handling for failed messages.Fix SPF/DKIM alignment for every sender in your reports, then step up to quarantine.
No DMARC record foundThe domain publishes no DMARC handling preference or aggregate-report request. It also fails major bulk-sender requirements.Publish v=DMARC1; p=none with a rua address at _dmarc.yourdomain.com today, then walk it up.
More than one DMARC recordMultiple records are discarded during DMARC policy discovery under RFC 9989.Delete every TXT record at _dmarc except one.
Syntax error or unknown tagReceivers may ignore the whole record. v=DMARC1 must be the first tag, tags are semicolon-separated.Rebuild the record with the free DMARC generator and re-publish it.
Legacy pct tagRFC 9989 removed pct because receivers applied intermediate percentages inconsistently.Use reports and controlled policy changes to stage enforcement; remove legacy pct after reviewing interoperability.
No rua tagNo aggregate reports are requested, reducing the evidence available for sender inventory and policy changes.Add rua=mailto:… so enforcement decisions are driven by data.
sp weaker than pExisting subdomains carry a looser requested policy than the organizational domain.Inventory legitimate subdomain senders, then let them inherit p or set an intentional sp policy.

What this checker can prove

The checker proves what public DNS returns at the DMARC policy name and whether the record's tags parse into a usable policy. Its interpretation follows the current RFC 9989 DMARC standard. It cannot prove that a production message passed SPF or DKIM, discover every legitimate sender, or predict a receiver's private handling decision. Use a real message header and aggregate-report evidence for those questions.

For a benchmark beyond one domain, Palisade's State of DMARC 2026 analyzes enforcement across the top 100,000 domains and documents the methodology behind the result.

From a public result to an enforcement workflow

A one-shot check shows you today's problem. Getting to enforcement is the actual work: reading aggregate reports, aligning SPF and DKIM for every legitimate sender, and tightening the policy without disrupting real mail. Palisade turns those reports into a prioritized workflow so operators can identify senders, investigate alignment failures, review proposed record changes, and progress each domain toward enforcement with evidence.

For MSPs it's built multi-tenant: every client domain checked, remediated, and enforced from one console, with portfolio-based per-client-domain pricing whose rate improves as you scale, without metering client email volume.

Related checks and terms

What is DMARC? Email authentication explained

DMARC software that does the work

Palisade organizes DMARC report evidence into prioritized sender and alignment work, helping operators review changes and move domains toward enforcement from one console.

Get startedBook a demo

1 domain free up to 1,000 emails/month

Email authentication knowledge base