DMARC Record Generator

· Free browser tool

A DMARC record generator assembles the single v=DMARC1 TXT record that tells receiving mail servers what to do with messages that fail SPF and DKIM checks for your domain. Get the policy, alignment, and reporting tags right and you gain visibility into who sends mail as your domain, and the leverage to stop spoofing; get one tag wrong and reports silently stop arriving while you assume you are protected.

This tool builds the record from plain inputs, includes only the tags that differ from their defaults in the conventional order, shows the exact _dmarc host to publish, and flags the mistakes that quietly break DMARC, such as enforcing a policy with nowhere to send reports. It is free and runs entirely in your browser, so nothing you type is uploaded.

DMARC Record GeneratorFree · client-side
The record is published as a TXT at _dmarc.example.com
Share of failing mail the policy is applied to. Default 100; leave blank to omit.
Where daily XML reports are sent. One or more addresses, comma-separated.
Per-message failure samples. Few receivers honour this; leave blank if unsure.
DNS record to publish
TypeTXT Host / name _dmarc Valuethe record below

      

🔒 Private: everything runs in your browser. Nothing you paste is uploaded.

How to use the DMARC record generator

Pick a policy, add a reporting address, and the valid TXT record builds as you type. Copy the record, then publish it as a TXT entry at the _dmarc host shown above the output.

Start at p=none, then tighten to quarantine and reject

The policy tag p= is the only required tag after v=DMARC1 and it must come first. Begin with p=none, which takes no action but turns on aggregate reporting, and leave it there for a few weeks so the daily reports reveal every service sending mail as your domain. Once SPF and DKIM pass for all of those legitimate senders, move to p=quarantine to push failures to spam, and finally to p=reject to block them outright. Jumping straight to reject before your sources are aligned is the fastest way to lose real mail.

Always set an rua address before you enforce

The rua= tag is where receivers send daily aggregate XML reports, and it is formatted as mailto: followed by the address. Without it you enforce blind: mail gets quarantined or rejected and you have no record of what or why. The generator warns when a quarantine or reject policy has no rua= set, because that combination is almost always a mistake. If reports go to a mailbox on a different domain than the one you protect, that domain must publish an external authorisation record before any receiver will deliver reports to it.

Leave defaults alone and use pct for a staged rollout

A clean DMARC record carries only the tags that differ from their defaults, so this tool omits adkim, aspf, ri, and pct when you leave them at relaxed alignment, the 86400-second interval, and 100 percent. Strict alignment is rarely needed and breaks common forwarding and subdomain setups, so keep relaxed unless you have a specific reason. The pct= tag applies your policy to a sampled share of failing mail, which is useful for easing into quarantine on a high-volume domain, but it has no effect under p=none since none never acts.

DMARC record generator frequently asked questions

Q1Where do I publish the DMARC record?

Publish it as a single TXT record at the host _dmarc on your domain, so the full name is _dmarc.yourdomain.com. The value is the v=DMARC1 string this tool generates. Most DNS panels ask for the host or name separately from the value, so enter _dmarc as the host and paste the record as the value. Allow time for DNS to propagate, then verify with a DMARC lookup before relying on it.

Q2What is the difference between p=none, quarantine, and reject?

The p= policy tells receivers how to treat mail that fails DMARC. none takes no action and only collects reports, making it the safe starting point. quarantine sends failing mail to the spam or junk folder. reject blocks failing mail outright so it is never delivered. The standard path is none to quarantine to reject, moving up only after reports confirm your legitimate senders pass SPF and DKIM.

Q3Do I need both rua and ruf addresses?

No. The rua tag for aggregate reports is the one that matters and you should always set it, because those daily summaries show every sender and alignment result for your domain. The ruf tag for forensic reports sends per-message failure samples that can include message content, and most large receivers no longer honour it. Set rua for visibility, and add ruf only if you have a specific need and a mailbox cleared to receive that data.

Q4What does adkim and aspf strict alignment do?

Alignment controls how closely the domain in SPF or DKIM must match the visible From domain. Relaxed, the default, allows subdomains to match the organisational domain, which suits most setups. Strict requires an exact match. Strict alignment frequently breaks legitimate mail from subdomains, forwarders, and third-party senders, so this tool keeps relaxed as the default and only adds the tag when you deliberately choose strict.

Q5Does this DMARC generator send my domain or addresses anywhere?

No. The record is assembled entirely in your browser with client-side JavaScript. Your domain, policy, and reporting addresses are never uploaded, logged, or stored, and the tool keeps working offline once the page has loaded. That makes it safe to draft records for internal or unannounced domains without exposing them, and you only publish the record yourself when you add it to DNS.

Hristo Bogdanov, Head of SEO at SEO Domains

Hristo Bogdanov

Head of SEO @ SEO Domains · CEO & Co-founder of SEO.bo

Hristo has spent 15+ years building aged-domain acquisition and screening workflows for SEO professionals, brand owners, and domain investors, and builds the free tooling SEO Domains publishes for practitioners.