DMARC (Domain-based Message Authentication, Reporting and Conformance), defined in RFC 7489, builds on SPF and DKIM to tell receiving mail servers how to handle messages that claim to be from your domain but fail authentication.
You publish a single TXT record at _dmarc.yourdomain.com. It carries a policy in the p= tag: none (monitor only), quarantine (send to spam), or reject (block outright). A message passes DMARC when either SPF or DKIM passes and the authenticated domain aligns with the address in the visible From header.
The rua= tag requests aggregate XML reports so you can see who sends as your domain; ruf= requests forensic samples. Tags like sp= set a subdomain policy and pct= roll a policy out gradually. Only one DMARC record per domain is valid; duplicates void the policy.
DMARC stops exact-domain spoofing and is a prerequisite for BIMI. Moving from none to reject safely takes patience; DMARC Engine handles that enforcement journey for you. Check your record with the tools below.
Check it on your domain
- DMARC Checker: look up and validate a domain's DMARC record and policy.
- DMARC Generator: build a valid DMARC record from a simple form.
- DMARC Report Analyser: read a DMARC aggregate (RUA) report in plain English.