Look up the DMARC record at _dmarc.domain, read its policy, alignment and reporting tags in plain terms, and check that the addresses receiving your reports have agreed to. Free, no sign-up, runs in your browser.
SPF and DKIM each authenticate a domain, not necessarily the one in the From address your reader sees. DMARC (RFC 7489) ties them to it: a message passes when SPF or DKIM passes and the authenticated domain matches the From domain. The record then tells receivers what to do with mail that fails, and where to send daily reports about it.
The usual path is to start at p=none with reporting on, use the reports to find every service that sends as you, fix their alignment, then move to quarantine and finally reject. A domain left at p=none is monitored, not protected.
p=The policy: none (monitor), quarantine (spam folder) or reject (refuse).
sp=Policy for subdomains. Defaults to p. Setting sp=none under an enforced p leaves subdomains open to spoofing.
rua=Where aggregate reports go. Addresses on another domain only receive reports if that domain publishes an authorization record.
adkim= / aspf=Alignment mode. Relaxed (default) accepts subdomains of the From domain; strict requires an exact match.
pct=Applies the policy to a share of failing mail. Useful for ramping up; removed in DMARCbis, so plan to reach 100.
ruf=Per-message failure reports. Most large providers never send them, for privacy reasons.
It is the right place to start and the wrong place to stay. At p=none spoofed mail is still delivered; you only get reports. Once those reports show your real senders passing, move to quarantine.
Check that rua= is a valid mailto: address. If it is on another domain (a DMARC reporting service, say), that domain must publish yourdomain._report._dmarc.theirdomain. This checker tests for it.
No. Subdomains inherit the organizational domain's record and its sp= policy. Publish a separate record only when a subdomain needs a different policy.
Any service sending as your domain without aligned SPF or DKIM: often a CRM, help desk, invoicing tool or website contact form. Our DMARC report analyzer lists them from your aggregate reports.
Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.
curl "https://powerline.ai/api/tools/dmarc?domain=example.com"
Drop in DMARC aggregate reports (XML, .gz, .zip) to see pass rates, failing sources and what to fix.
Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.
Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.
SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.
See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.