What it checks
The DMARC record at _dmarc under the domain: whether it exists and parses, how strict its policy is, whether it applies to all mail and whether it asks for reports.
A pass means: A DMARC policy tells receivers what to do with mail that fails checks.
Possible findings
No DMARC policy
Severity: MediumConfidence: ConfirmedKind: Security issue
What we found
No DMARC record was found at _dmarc for the domain.
Why it matters
DMARC tells receivers what to do with mail that fails SPF and DKIM, and sends you reports about who sends as your domain. Without it, spoofed mail is much more likely to be delivered.
How to fix it
Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.
DMARC is in monitoring mode
Severity: LowConfidence: ConfirmedKind: Recommended hardening
What we found
The DMARC policy is p=none, which reports on failures but does not stop them.
Why it matters
Monitoring mode is the right first step, but it does not protect anyone from spoofed mail until the policy is raised.
How to fix it
Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.
DMARC record has errors
Severity: MediumConfidence: High confidenceKind: Security issue
What we found
The DMARC record could not be parsed.
Why it matters
Receivers ignore a malformed DMARC record, so the domain is treated as having no policy.
How to fix it
Correct the record. It must start with v=DMARC1; followed by a p= tag (none, quarantine or reject).
DMARC applies to only part of the mail
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
The DMARC policy sets pct below 100.
Why it matters
Only a sample of failing mail is subject to the policy. This is useful while rolling out, but leaves the rest unprotected.
How to fix it
Remove the pct tag (it defaults to 100) once you are confident in the policy.
DMARC reports are not requested
Severity: InformationConfidence: ConfirmedKind: Recommended hardening
What we found
The DMARC record has no rua tag, so you receive no aggregate reports.
Why it matters
Without reports you cannot see who is sending mail as your domain, or whether legitimate mail is failing.
How to fix it
Add rua=mailto: with an address or a DMARC reporting service.

