How to use the DMARC record generator
Enter your domain, choose a policy, add an email address for reports, and copy the TXT record the generator gives you. Publish it at _dmarc on your domain. Google says to run SPF and DKIM for at least 48 hours before you turn DMARC on.
Before you start
You need four things.
- SPF or DKIM already working for your domain. Google says a message passes DMARC when it passes SPF with alignment or DKIM with alignment. Set up both if you can, with the free SPF record generator and DKIM generator.
- Access to the DNS settings of your domain, usually at your domain host.
- A mailbox, or a group, that only receives DMARC reports. Google advises a dedicated mailbox or group, or a third party DMARC service, over a personal address.
- A list of every service that sends email as your domain.
Fill in the generator
| Field | What to enter | Example |
|---|---|---|
| Domain name | The domain in your From address | example.com |
| Policy | none, quarantine or reject | none |
| Subdomain policy | Optional. Leave blank to give subdomains the same policy | blank |
| Percentage | Optional. A whole number from 1 to 100. Leave blank for 100 | blank |
| Report email address | The mailbox that receives reports | dmarc@example.com |
| DKIM alignment | Relaxed or strict | Relaxed |
| SPF alignment | Relaxed or strict | Relaxed |
Select Generate and copy the record. The generator leaves out any tag you keep at its default.
Choose a policy
| Policy | What the receiver does with a message that fails | When to use it |
|---|---|---|
none | Takes no action and delivers the message | First stage. It also satisfies Google's rule for bulk senders |
quarantine | Marks the message as spam and sends it to the spam folder | After reports show that every real sender passes |
reject | Rejects the message. The receiving server usually sends a bounce to the sender | After quarantine has run without problems |
Google says to start with p=none and change to quarantine or reject over time. The right moment depends on your reports, not on a calendar date.
Choose an alignment mode
Pick relaxed for both. Relaxed is the default, and Google says it gives enough protection against spoofing in most cases. Google also warns that strict alignment can send mail from related subdomains to spam or get it rejected.
Publish the record
Add one TXT record at your DNS host with these values.
| Field | Value |
|---|---|
| Type | TXT |
| Host, Name or Alias | _dmarc |
| Value | The record from the generator |
| TTL | The default your host offers |
Some DNS hosts add your domain to the end of the host name for you. If yours does, enter _dmarc and not _dmarc.example.com.
A domain can have only one DMARC record. RFC 9989 says a receiver discards every DMARC record it finds when two or more sit at the same name. Edit the record you have and do not add a second.
Subdomains use the policy of the main domain unless the record sets sp.
Example DMARC records
These three records are examples. Replace dmarc@example.com with your own report address.
| Stage | Record |
|---|---|
| Monitor only | v=DMARC1; p=none; rua=mailto:dmarc@example.com |
| Spam folder for half of failing mail | v=DMARC1; p=quarantine; pct=50; rua=mailto:dmarc@example.com |
| Reject failing mail | v=DMARC1; p=reject; rua=mailto:dmarc@example.com |
The pct=50 value is an example number chosen for this page. Google says to raise pct gradually until it reaches 100.
To send reports to more than one mailbox, put a comma between the addresses and give each one its own mailto:.
If the report address sits on a different domain from the one you protect, add a DNS TXT record at that other domain. Google states this as a requirement. The generator shows you that record when it is needed.
Check that it works
- Confirm your DNS host shows the new
_dmarcrecord. - Send a message to a Gmail address you can open.
- Open the message, select More next to Reply, then select Show original. Google also links to its Admin Toolbox Messageheader tool, where you paste the headers.
- Read the DMARC result. A passing message shows pass.
- Check the report mailbox the next day. Google says DMARC reports usually arrive once a day, as XML files, from each mail server you send to.
Each report lists the servers that send mail for your domain, what share of your messages pass DMARC, and the action each receiver took. Google says large organizations can get hundreds or thousands of reports a day.
Fix common DMARC problems
| What you see | Cause | Fix |
|---|---|---|
| No DMARC result at all | The record does not start with v=DMARC1. RFC 9989 says a record is ignored when v is not the first tag. | Put v=DMARC1 first, spelled exactly like that. |
| No DMARC result at all, and two records sit at _dmarc | A receiver discards every DMARC record when it finds more than one. | Merge them into one record and delete the other. |
| No DMARC result at all, and the record looks right | The host name is wrong, often _dmarc.example.com.example.com. | Enter _dmarc if your DNS host adds the domain for you. |
| dmarc fails although SPF and DKIM pass | The domain that passed SPF or DKIM does not match the From domain. Google lists a misaligned header as a cause. | Sign mail with DKIM using your own domain, or send with your own domain in the return path. |
| Mail from a subdomain goes to spam or is rejected | Strict alignment is on. | Set both alignment modes back to relaxed. |
| A bounce shows 5.7.26 | A message failed DMARC and the policy told the receiver to act on it. | Set the policy back to none. Fix SPF and DKIM for the sender, then move up again. |
| A real service starts failing after you raise the policy | That service is missing from SPF and does not sign with DKIM. | Read the reports to find its server, then add it to SPF or set up DKIM for it. |
| No reports arrive | The record has no rua tag. RFC 9989 says receivers must not send aggregate reports without it. | Add rua=mailto: and your address. |
| No reports arrive and rua is present | The report address is on another domain with no approval record there. | Add the TXT record that Google describes at the other domain. |
Why TrueEmailer for deliverability
A message passes DMARC only when SPF or DKIM passes and lines up with the From domain. Google lists alignment as one of the causes of DMARC failure. Google also requires senders above 5,000 messages a day to publish DMARC, and says a policy of p=none is acceptable for that rule.
A DMARC record that sits on top of broken SPF or DKIM only creates failures. The order matters, and each step needs the one before it.
TrueEmailer is built around that order.
- SPF, DKIM and DMARC are configured at setup, so no campaign starts without a record in place.
- Mail leaves from pre warmed SMTP infrastructure. See deliverability and warmup.
- The generator on this page writes the record in the order the standard requires, with
v=DMARC1first.
A passing DMARC check shows that a message is allowed to use your domain. It does not set your reputation. Complaint rates, list quality and message content still decide where mail lands, and no tool removes that work. Keep your list clean with the free email verifier.
DMARC record generator FAQ
Do I need DMARC if I send fewer than 5,000 messages a day?
+
Google requires DMARC from senders above 5,000 messages a day. Smaller senders must still use SPF or DKIM. A DMARC record also gives you reports on who sends mail as your domain.
Can I start with p=none?
+
Yes. Google tells admins to start with p=none, and the bulk sender rule accepts it.
How long until DMARC works?
+
Google gives no wait time for the DMARC record itself. It says SPF and DKIM should run for at least 48 hours before you turn DMARC on. Reports arrive about once a day, so give it a day before you read them.
How many DMARC records can one domain have?
+
One. A receiver discards every record when two or more sit at the same name.
Do subdomains need their own record?
+
No. Subdomains use the main policy unless you set a different one with the subdomain policy field.
Where do the reports go?
+
They go to the address in the rua tag. They arrive as XML files, so use a mailbox or group that only handles reports.
Checked 8 October 2026 against RFC 9989 and Google Workspace Help.