DMARC Engine
Home/Free tools/DMARC Generator
Free tool · DMARC

DMARC Generator

Build a valid DMARC record from a simple form.

Build a valid DMARC record for your domain, then copy and paste it into your DNS. Start at p=none to watch your mail without blocking anything, then move up to p=reject once your legitimate senders are aligned. Everything happens in your browser. Nothing is sent or stored.

The domain you send mail from. Used only to show where the record goes.
Tells mailbox providers what to do with mail that fails DMARC.
Leave as "same" unless subdomains need a different rule.
Where daily XML summaries are sent. Strongly recommended.
Per-message failure reports. Few providers send these.
Optional policy for non-existent subdomains.
Applies one policy level lower while you validate the next stage.
Controls when forensic reports are generated.
Relaxed allows subdomains to align. Strict requires an exact match.
Relaxed allows subdomains to align. Strict requires an exact match.

The DMARC Generator creates a current RFC 9989 v=DMARC1 policy record from plain choices.

What the tags mean

p sets the Author Domain policy; sp covers subdomains and np can cover non-existent subdomains. t=y is the current test mechanism and asks receivers to apply one policy level lower. rua requests aggregate reports; ruf requests privacy-sensitive failure reports that many receivers do not send. adkim and aspf control alignment.

Publishing and rolling out

Publish one TXT policy at _dmarc.yourdomain.com. Start with p=none, identify and align every legitimate service from aggregate reports, test quarantine with p=quarantine; t=y, then enforce quarantine. Repeat that evidence gate with p=reject; t=y before full reject. Legacy pct, rf and ri are recognized when inspecting old records but are not generated as current configuration.

Frequently asked questions

Which policy should I generate first?

Start with p=none and a working rua. Do not advance until every legitimate sender is identified and aligned.

What does t=y do?

RFC 9989 test mode applies one policy level lower: reject is tested as quarantine, and quarantine is tested as none.

Can I point rua at a different domain?

Yes, but that external destination must publish the required DMARC report-receiver authorization.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.