Skip to content

Email security

DMARC checker

Look up a domain's DMARC record and read what it tells receiving mail servers: whether to reject, quarantine or merely report mail that fails SPF and DKIM, for how much of it, and where the reports go.

Checked from Ironfang Security's scanner address with the same low-impact limits as a scan. Nothing you enter is kept.

What this checks

What the result means

A DMARC record tells receivers what the owner of a domain wants done with mail that claims to come from it but fails both SPF and DKIM alignment. Without one, each receiver decides for itself, and mail forged in your name is judged only on its other signals.

p=none asks receivers to deliver failing mail as normal and only report it. It is the right place to start, while reports show which services send for you, but it protects nothing. p=quarantine asks for failing mail to be treated as suspicious, usually sent to spam, and p=reject asks for it to be refused.

A passing result means a valid record with an enforcing policy for all mail and reporting switched on. A finding names the one thing to change, and Ironfang's check reference explains why it matters.

How to fix common issues

No DMARC policy

Publish a TXT record at _dmarc.example.com such as v=DMARC1; p=none; rua=mailto:dmarc@example.com, review the reports, then move to p=quarantine and p=reject.

More in the DMARC check reference

DMARC is in monitoring mode

Once reports show your legitimate mail passing, move to p=quarantine and then p=reject.

More in the DMARC check reference

DMARC applies to only part of the mail

Remove the pct tag (it defaults to 100) once you are confident in the policy.

More in the DMARC check reference

DMARC reports are not requested

Add rua=mailto: with an address or a DMARC reporting service.

More in the DMARC check reference

DMARC record has errors

Correct the record. It must start with v=DMARC1; followed by a p= tag (none, quarantine or reject).

More in the DMARC check reference

Cyber Essentials and ISO 27001

Neither Cyber Essentials nor ISO 27001 names DMARC. A DMARC policy is technical evidence for the broader controls they do require: secure configuration of internet-facing services, and protecting information sent by email (ISO/IEC 27001:2022 Annex A 5.14, information transfer).

The organisation still has to establish who owns mail security, how the services allowed to send as the domain are approved, how reports are reviewed and how changes to the record are authorised. A record shows the setting, not the process behind it.

Scope and limitations

Related guides

Questions

What does p=none mean?
It asks receivers to deliver mail that fails DMARC as normal and send you reports about it. Use it while you find every service that sends as your domain, then move to quarantine and reject.
Does a subdomain need its own DMARC record?
No. A subdomain without a record is covered by its organisational domain's record, using the sp= policy if it sets one and p= otherwise. A subdomain that sends differently can have its own.
Will moving to p=reject stop my own mail?
Only mail that fails both SPF and DKIM alignment. Read the aggregate reports first: any legitimate service that fails needs SPF or DKIM set up for your domain before you enforce.

Related security tools