DMARC record checker

Look up the DMARC record at _dmarc.domain, read its policy, alignment and reporting tags in plain terms, and check that the addresses receiving your reports have agreed to. Free, no sign-up, runs in your browser.

If the domain has no record of its own, the organizational domain's record is found and its subdomain policy applied, the way receivers do it.

How it works

What DMARC adds on top of SPF and DKIM

SPF and DKIM each authenticate a domain, not necessarily the one in the From address your reader sees. DMARC (RFC 7489) ties them to it: a message passes when SPF or DKIM passes and the authenticated domain matches the From domain. The record then tells receivers what to do with mail that fails, and where to send daily reports about it.

The usual path is to start at p=none with reporting on, use the reports to find every service that sends as you, fix their alignment, then move to quarantine and finally reject. A domain left at p=none is monitored, not protected.

p=

The policy: none (monitor), quarantine (spam folder) or reject (refuse).

sp=

Policy for subdomains. Defaults to p. Setting sp=none under an enforced p leaves subdomains open to spoofing.

rua=

Where aggregate reports go. Addresses on another domain only receive reports if that domain publishes an authorization record.

adkim= / aspf=

Alignment mode. Relaxed (default) accepts subdomains of the From domain; strict requires an exact match.

pct=

Applies the policy to a share of failing mail. Useful for ramping up; removed in DMARCbis, so plan to reach 100.

ruf=

Per-message failure reports. Most large providers never send them, for privacy reasons.

FAQ

Common questions.

Is p=none bad?

It is the right place to start and the wrong place to stay. At p=none spoofed mail is still delivered; you only get reports. Once those reports show your real senders passing, move to quarantine.

Why are my reports not arriving?

Check that rua= is a valid mailto: address. If it is on another domain (a DMARC reporting service, say), that domain must publish yourdomain._report._dmarc.theirdomain. This checker tests for it.

Do I need DMARC on subdomains?

No. Subdomains inherit the organizational domain's record and its sp= policy. Publish a separate record only when a subdomain needs a different policy.

What breaks when I move to reject?

Any service sending as your domain without aligned SPF or DKIM: often a CRM, help desk, invoicing tool or website contact form. Our DMARC report analyzer lists them from your aggregate reports.

For agents and pipelines

The same check, as an API and an MCP tool.

Point an MCP client (Claude, Cursor, any agent) at https://powerline.ai/mcp and call check_record, or hit the JSON endpoint directly. No key, no account.

dmarc.sh
curl "https://powerline.ai/api/tools/dmarc?domain=example.com"
More free tools

Keep going.

DMARC Report Analyzer

Drop in DMARC aggregate reports (XML, .gz, .zip) to see pass rates, failing sources and what to fix.

SPF Checker

Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.

DKIM Checker

Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.

Email Domain Check

SPF, DKIM, DMARC, MX, MTA-STS, TLS-RPT, BIMI and blacklists in one run, scored out of 100 with a fix list.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools