Email security
DMARC checker
Look up a domain's DMARC record and read what it tells receiving mail servers: whether to reject, quarantine or merely report mail that fails SPF and DKIM, for how much of it, and where the reports go.
What this checks
- The TXT record at
_dmarc.<domain>, and for a subdomain without one, the record at its organisational domain, which then applies to it. - Whether there is exactly one DMARC record and whether it parses:
v=DMARC1first, a validp=policy, and validsp=andpct=values. - The policy that applies:
none,quarantineorreject, with the subdomain policy where one is set. - Whether the policy covers all failing mail (
pct=100, the default) or only part of it. - Whether aggregate reports are requested with a
rua=mailto:address.
What the result means
A DMARC record tells receivers what the owner of a domain wants done with mail that claims to come from it but fails both SPF and DKIM alignment. Without one, each receiver decides for itself, and mail forged in your name is judged only on its other signals.
p=none asks receivers to deliver failing mail as normal and only report it. It is the right place to start, while reports show which services send for you, but it protects nothing. p=quarantine asks for failing mail to be treated as suspicious, usually sent to spam, and p=reject asks for it to be refused.
A passing result means a valid record with an enforcing policy for all mail and reporting switched on. A finding names the one thing to change, and Ironfang's check reference explains why it matters.
How to fix common issues
No DMARC policy
Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.
DMARC is in monitoring mode
Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.
DMARC applies to only part of the mail
Remove the pct tag (it defaults to 100) once you are confident in the policy.
DMARC reports are not requested
Add rua=mailto: with an address or a DMARC reporting service.
DMARC record has errors
Correct the record. It must start with v=DMARC1; followed by a p= tag (none, quarantine or reject).
Cyber Essentials and ISO 27001
Neither Cyber Essentials nor ISO 27001 names DMARC. A DMARC policy is technical evidence for the broader controls they do require: secure configuration of internet-facing services, and protecting information sent by email (ISO/IEC 27001:2022 Annex A 5.14, information transfer).
The organisation still has to establish who owns mail security, how the services allowed to send as the domain are approved, how reports are reviewed and how changes to the record are authorised. A record shows the setting, not the process behind it.
Scope and limitations
- The check reads public DNS through public resolvers. It does not see your mail flow, so it cannot tell whether legitimate senders already pass SPF and DKIM alignment; aggregate reports tell you that before you enforce.
- It does not send or receive email and does not test how a particular receiver applies the policy.
- Optional tags such as
adkim,aspf,rufandfoare shown with what they mean but are not judged.
Related guides
Questions
- What does p=none mean?
- It asks receivers to deliver mail that fails DMARC as normal and send you reports about it. Use it while you find every service that sends as your domain, then move to quarantine and reject.
- Does a subdomain need its own DMARC record?
- No. A subdomain without a record is covered by its organisational domain's record, using the sp= policy if it sets one and p= otherwise. A subdomain that sends differently can have its own.
- Will moving to p=reject stop my own mail?
- Only mail that fails both SPF and DKIM alignment. Read the aggregate reports first: any legitimate service that fails needs SPF or DKIM set up for your domain before you enforce.
Related security tools
- SPF checker - Check a domain's SPF record, its all mechanism and how many of the 10 DNS lookups it uses.
- DKIM checker - Look up a DKIM key at your selector or at common ones, with its key type and size.
- Email security checker - Check MX, SPF, DMARC and DKIM together, and the protection of a domain that sends no mail.
- Website security checker - Check a domain's DNS, email authentication, TLS, security headers and public technology in one pass.

