DMARC Record Builder Guide
DMARC tells receivers what to do when SPF or DKIM fails, and where to send reports. Start at p=none so mail is not quarantined while you read those reports. The builder will not produce a record without a report address.
Overview
The host name is _dmarc plus your domain, for example _dmarc.example.com. The draft looks like v=DMARC1; p=none; rua=mailto:dmarc@example.com. Move to quarantine or reject only after reports show that legitimate mail already passes SPF or DKIM alignment. This page does not publish DNS and does not start Mail Watch.
What to check before you publish
- Policy: Keep p=none until reports look clean.
- Reports: rua is required. Use a mailbox you actually read.
- Host: Publish the TXT record at _dmarc.your-domain, not at the bare domain.
DMARC draft checklist
| Tag | Draft default | Why it matters |
|---|---|---|
| p | none | Monitor without changing delivery |
| rua | Required mailto | Aggregate reports show who is sending |
| host | _dmarc.domain | Receivers look up this name |
Example draft
Monitor-only DMARC
Host: _dmarc.example.com
v=DMARC1; p=none; rua=mailto:dmarc@example.comRecommended Remediation Flow
- Draft the record Enter the domain and a report mailbox. Leave policy at p=none.
- Publish it yourself Create a TXT record at the _dmarc host shown on the page.
- Check the live record Use Check this domain. DKIM and SPF alignment stay relaxed unless you choose Strict. Percentage stays at 100 unless you change it.
Troubleshooting Common Issues
Reports never arrive
The mailbox or host name may be wrong.
- Confirm the TXT name is _dmarc.your-domain.
- Confirm rua is a real mailbox.
- Wait a day; aggregate reports are not instant.
Validation Checklist
Post-fix validation
- The live TXT is at _dmarc.your-domain.
- Policy is p=none until you choose otherwise.
- Mail Watch was not started by this page.
FAQ
Does this start Mail Watch?
No.
- This is a free draft tool.
- Mail Watch is a separate paid product.
- You still publish the DNS record yourself.