DMARC Analyzer

What is DMARC?

← All help articles · DMARC fundamentals

DMARC (Domain-based Message Authentication, Reporting and Conformance, RFC 7489, updated by RFC 9989/9990/9991) is a DNS TXT record published at _dmarc.yourdomain.com. It does two things: sets a policy (p=) telling receivers what to do with mail claiming to be from your domain that fails authentication, and requests aggregate reports (rua=) — daily summaries of who is sending mail as your domain and whether it passed.

DMARC itself does not authenticate anything directly. It relies on SPF and DKIM, and adds one more requirement on top: alignment between the authenticated domain and the visible From: address.

This tool exists to make the aggregate reports DMARC generates actually readable, and to help you move a domain safely from p=none toward p=reject without breaking legitimate mail.

If the health check reports "no DMARC record found": publish one at _dmarc.yourdomain.com. A safe starting point that only monitors, changing nothing about delivery: v=DMARC1; p=none; rua=mailto:you@yourdomain.com — see p=none for why that's the right first step. Once a domain is already onboarded here, set that rua= address to this tool's own mailbox so its reports actually reach the dashboard — see the domain page's "Cross-domain report authorization" card for the exact address and any extra DNS record needed.

If the health check instead shows "inherits policy from organizational domain X": that's not a problem — see organizational domain & the DNS tree walk for what that means and why it's a normal, fully valid DMARC deployment pattern.

References