What this generator does differently
Most DMARC generators assemble tags and stop there. But syntax is rarely the actual problem with DMARC — almost every published record is syntactically fine and has still stalled at the wrong point of the rollout.
So every draft you build in the form is then run through the same audit function that grades other people's records on the check page. What you read under "Audit" is exactly what the checker would say about your record once published. On top of that come pointers naming the next step rather than just the current state.
Adjusting an existing record
Enter the domain and press "Build record": if a record is already published under
_dmarc.yourdomain, it is read and pre-fills the fields. You then change only what
you want to change — and see, tag by tag, what differs from the published state. Unrecognised
or rarely used tags are not silently dropped; they show up in the comparison.
The order in which DMARC is rolled out
p=nonewithrua— changes nothing about delivery but produces the aggregate reports. Withoutrua,p=noneis pointless: you block nothing and learn nothing.- Read the reports — two to four weeks. They tell you which systems send in your name. In practice that is more than anyone initially knows about.
p=quarantine— failing mail lands in the spam folder rather than nowhere. If you want to be careful, step through it withpct.p=reject— only once nothing unfamiliar shows up in the reports.
That is why the generator starts at p=none, not at p=reject.
The tags one by one
p— what the receiver should do with mail that fails DMARC:none,quarantineorreject.sp— the same for subdomains. If absent, subdomains inheritp. That is usually right; set it only to deviate deliberately.rua— address for the daily aggregate reports. The single most important tag. Written without a scheme? The generator addsmailto:.ruf— forensic reports on individual messages. Few receivers send them, and they can contain content — awkward under data protection law.pct— the percentage of messages the policy is applied to. Only meaningful together withquarantineorreject.adkim/aspf— alignment.r(relaxed) allows subdomains as senders,s(strict) demands an exact match.fo— when a forensic report is triggered.ri— aggregate report interval in seconds. The default of 86400 (daily) is what nearly every receiver uses anyway.
Publishing
The record goes in as a TXT entry on the name
_dmarc.yourdomain — not on the domain itself. After creating it, the TTL decides
how long the change takes to become visible everywhere; you can look at any time with the
DMARC check.