Enter a domain — an existing DMARC record is loaded into the fields below.

What this generator does differently

Most DMARC generators assemble tags and stop there. But syntax is rarely the actual problem with DMARC — almost every published record is syntactically fine and has still stalled at the wrong point of the rollout.

So every draft you build in the form is then run through the same audit function that grades other people's records on the check page. What you read under "Audit" is exactly what the checker would say about your record once published. On top of that come pointers naming the next step rather than just the current state.

Adjusting an existing record

Enter the domain and press "Build record": if a record is already published under _dmarc.yourdomain, it is read and pre-fills the fields. You then change only what you want to change — and see, tag by tag, what differs from the published state. Unrecognised or rarely used tags are not silently dropped; they show up in the comparison.

The order in which DMARC is rolled out

  1. p=none with rua — changes nothing about delivery but produces the aggregate reports. Without rua, p=none is pointless: you block nothing and learn nothing.
  2. Read the reports — two to four weeks. They tell you which systems send in your name. In practice that is more than anyone initially knows about.
  3. p=quarantine — failing mail lands in the spam folder rather than nowhere. If you want to be careful, step through it with pct.
  4. p=reject — only once nothing unfamiliar shows up in the reports.

That is why the generator starts at p=none, not at p=reject.

The tags one by one

  • p — what the receiver should do with mail that fails DMARC: none, quarantine or reject.
  • sp — the same for subdomains. If absent, subdomains inherit p. That is usually right; set it only to deviate deliberately.
  • rua — address for the daily aggregate reports. The single most important tag. Written without a scheme? The generator adds mailto:.
  • ruf — forensic reports on individual messages. Few receivers send them, and they can contain content — awkward under data protection law.
  • pct — the percentage of messages the policy is applied to. Only meaningful together with quarantine or reject.
  • adkim / aspf — alignment. r (relaxed) allows subdomains as senders, s (strict) demands an exact match.
  • fo — when a forensic report is triggered.
  • ri — aggregate report interval in seconds. The default of 86400 (daily) is what nearly every receiver uses anyway.

Publishing

The record goes in as a TXT entry on the name _dmarc.yourdomain — not on the domain itself. After creating it, the TTL decides how long the change takes to become visible everywhere; you can look at any time with the DMARC check.

The full analysis

Send any email to hello@analyzemy.email and within seconds you get back a report with over 20 checks — for the actual sending IP, including DKIM, DMARC evaluation, the TLS path, blacklists and header analysis.

Analyze your email now

Last updated: · All checks at a glance