DMARC Checker
Check a domain's DMARC record and enforcement policy.
About this check
DMARC ties SPF and DKIM together and tells receivers what to do with mail that fails authentication. The policy is set with p=: "none" only monitors, while "quarantine" and "reject" actively block spoofed mail.
A DMARC record at _dmarc.yourdomain with p=quarantine or p=reject is the single most effective control against exact-domain spoofing. p=none provides visibility but no protection.
Frequently asked questions
What DMARC policy should I use?
Start at p=none to gather reports, then move to quarantine and finally reject once legitimate mail is aligned.
Do I need SPF and DKIM first?
Yes — DMARC evaluates SPF and DKIM alignment, so both should be in place before enforcing.
Want the full picture?
Get a complete security report with an exposure score across email, DNS, TLS, exposure and breach metadata.
Run a full report All tools