Check your DMARC record and see what it does to your mail.
We read your policy, reporting addresses and alignment, and tell you in plain English what happens to mail that fails.
Works with a domain or a full email address. We read DNS fresh on every run.
3 of 5 checks pass. Fix SPF first: until SPF passes, this domain falls short of the rules Gmail, Yahoo and Outlook set for bulk senders.
That meets the minimum Gmail and Yahoo ask of bulk senders, but mail that fails is still delivered, so anyone can send as this domain, and you will never hear about it.
v=DMARC1; p=none
Replace it with this record. Your DKIM key is in place, so mail signed with it passes DMARC. Quarantine is safe once the SPF fix above is live. If other services send as this domain, switch DKIM on in each of them first. Reports go to dmarc@trynorthpeak.example: create that address, or change it to one you read.
v=DMARC1; p=quarantine; rua=mailto:dmarc@trynorthpeak.example
Add it as a TXT record with host _dmarc in your DNS, in place of any DMARC record already there.
| v=DMARC1 | Marks this TXT record as DMARC. |
| p=none | The policy for mail that fails both SPF and DKIM alignment. Mail that fails is delivered as usual. You only get reports. |
We can set up your next sending domains with all five checks already passing.
We register the domains, create Google Workspace mailboxes with SPF, DKIM and DMARC in place, and connect them to Emailchaser with warm-up switched on. $6 a mailbox a month, plus $3 setup per mailbox and the domain ($16.59 a year for a .com). Ready in 24 to 48 hours.
The check runs on our server against live DNS and 16 public blocklists (3 for domains, 13 for mail server IPs). A list that does not answer is never counted as clean. Nothing you type is stored.
A DMARC record tells receivers what to do with mail that fails SPF and DKIM.
SPF and DKIM each answer a narrow question about a message. DMARC ties them to the address your recipient actually sees in From. A message passes DMARC when SPF or DKIM passes for the same domain as that From address, which is called alignment. When neither does, the receiver applies your policy: deliver it anyway (p=none), send it to spam (p=quarantine) or refuse it (p=reject).
Without a DMARC record, anyone can put your domain in the From line of their own mail, and receivers have no instruction from you about it. Gmail, Yahoo and Outlook all require a DMARC record from anyone sending in bulk, at p=none or stricter.
Every DMARC tag does one thing, and only v= and p= are required.
| Tag | Example | What it does |
|---|---|---|
| v | v=DMARC1 | Marks the record as DMARC. It must come first. |
| p | p=quarantine | The policy for mail that fails: none, quarantine or reject. |
| rua | rua=mailto:dmarc@yourdomain.com | Where receivers send daily summary reports. |
| sp | sp=reject | A separate policy for subdomains. Without it, subdomains follow p. |
| pct | pct=50 | Applies the policy to only part of failing mail, for a careful rollout. |
| adkim | adkim=s | Strict DKIM alignment: the signing domain must match exactly. Relaxed (r) is the default. |
| aspf | aspf=s | Strict SPF alignment, the same idea for the return-path domain. |
| ruf | ruf=mailto:... | Where to send copies of single failures. Outlook does not send these, and many receivers do not. |
| fo | fo=1 | When failure reports are sent: when either check fails, rather than both. |
The tags are defined in RFC 7489. Microsoft says it does not send ruf reports; read on 6 October 2026.
Most business domains have already moved past p=none.
We read the published records of the same 499 real business domains on every measurement, the kind of companies a cold emailer writes to. On 5 September 2026, 351 of them (70.3%) were at p=reject and only 6 had no DMARC record at all.
Their inbound mail is filtered by Proofpoint at 33.9% of them, Microsoft 365 at 26.1% and Google Workspace at 18.8%. All three check SPF, DKIM and DMARC on the mail they receive, which is why a domain that passes all five checks above is the minimum for cold email, not a bonus.
Source: Emailchaser Inbox Rules Index, 499 business domains, measured 5 Sep 2026 over public DNS. See the DMARC adoption rate.
DMARC enforcement runs from 97.6% in software to 57.1% in schools and universities.
The same measurement, split by what each company does. Enforced means p=quarantine or p=reject: the share of domains in each group that tell receivers to act on mail that fails.
| Sector | Domains measured | Enforce DMARC |
|---|---|---|
| Software | 126 | 97.6% |
| Finance | 54 | 94.4% |
| Services | 28 | 92.9% |
| Healthcare | 47 | 89.4% |
| Logistics | 17 | 88.2% |
| Retail | 50 | 88% |
| Travel | 25 | 88% |
| Energy | 24 | 87.5% |
| Media | 26 | 84.6% |
| Telecoms | 30 | 80% |
| Industrial | 44 | 79.5% |
| Schools and universities | 28 | 57.1% |
Source: Emailchaser Inbox Rules Index, measured 5 Sep 2026 over public DNS. Sector groups are small, so a few domains move a percentage a lot. See the DMARC adoption rate.
Move from p=none to p=reject in three steps, with reports telling you when.
- Start with reports. Publish
v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.comif you do not know every service that sends as your domain. Read a week or two of reports and list every sender in them. - Fix every legitimate sender. Switch DKIM on at each service that sends as you, so each one signs with your domain. The DKIM checker shows the keys you already have.
- Then enforce. Change p=none to p=quarantine. When the reports show only your own mail passing and nothing of yours failing, move to p=reject.
A brand-new cold email domain that only sends through one provider with DKIM on can skip the first step and start at p=quarantine. That is what our check suggests when it finds a working DKIM key. Microsoft's own advice for high-volume senders is the same order: none, then quarantine, then reject, once your legitimate sources are aligned (Microsoft, read 6 October 2026).
A DMARC report tells you every server that sent mail as your domain.
Once a record has a rua= address, receivers that send reports (Google and Yahoo among them) mail a compressed XML file there about once a day. Each file covers one receiver and one day, and each row in it is one sending server.
| Field in the report | What it tells you |
|---|---|
| source_ip | The server that sent the mail. Look it up to see which service it belongs to. |
| count | How many messages that server sent as your domain that day. |
| policy_evaluated: disposition | What the receiver did: none, quarantine or reject. |
| policy_evaluated: dkim and spf | Whether DKIM and SPF passed in a way that counts for DMARC, that is, aligned with your From domain. |
| auth_results | The raw DKIM and SPF results, with the domain each one checked. |
Read it in that order. A server you recognise with dkim pass is fine. A server you recognise with dkim fail is a service to fix before you enforce. A server you do not recognise, failing both, is someone sending as you, and exactly what p=quarantine and p=reject are for. A reporting service turns the XML into a readable table if the volume gets large.
Your DMARC record protects your domain, not the mail you send to others.
A DMARC record governs mail sent as your domain. It does not change how a recipient's server judges you: that comes from your SPF, DKIM and DMARC passing, and from your sending reputation. Publishing p=reject does not make your own campaigns land better, and a recipient's strict policy does not make your mail to them land worse.
What a strict policy does give you is a domain that nobody else can spoof, which keeps phishing in your name out of your recipients' inboxes and your domain off the lists that catch it. Build a record from scratch with the DMARC record generator, or check all five records on the domain health check.
Common questions about DMARC
What is a DMARC record?
A TXT record at _dmarc.yourdomain.com that tells receiving servers what to do with mail that claims to be from your domain but fails both SPF and DKIM alignment: deliver it, send it to spam, or refuse it. It also tells them where to send reports.
What does p=none do?
Nothing to the mail itself. Failing messages are delivered as usual, and you only get reports. It meets the minimum Gmail, Yahoo and Outlook ask of bulk senders, but it does not stop anyone sending as your domain.
Is it safe to move to p=quarantine?
Yes, once every service that sends as your domain passes SPF or DKIM for it. DKIM is the safer one to rely on, because it survives forwarding. Our check suggests quarantine when it finds a working DKIM key, and keeps you at p=none when it does not.
Where should DMARC reports go?
To an address someone reads, or a DMARC reporting service. The rua= tag takes one or more mailto: addresses. Reports are daily XML files from each receiver, listing every server that sent mail as your domain and whether it passed.
Does DMARC need both SPF and DKIM to pass?
No. A message passes DMARC when either one passes for a domain that matches the From address. DKIM is the one to rely on, because forwarding breaks SPF and leaves a DKIM signature intact.
What is the difference between rua and ruf?
rua= receives aggregate reports: one summary a day from each receiver, with counts per sending server. ruf= receives failure reports, with details of single failing messages. Most receivers send only aggregate reports, so rua= is the one that matters.
Does a subdomain need its own DMARC record?
No. A subdomain with no record of its own follows its parent domain's record, using the sp= policy if there is one and p= otherwise. Our check reads the parent's record in that case and says so.
Why do two DMARC records break DMARC?
A domain may publish exactly one. With more than one, receivers act as if there were none (RFC 7489), so your policy stops working. Our check shows the strictest of them as the one to keep.
More free tools for your sending setup
Send cold email from domains that pass all five checks.
Every plan includes warm-up, follow-ups and unlimited email accounts, from $47 a month.
Start my free trial7-day free trial, $0 today