What is a DMARC record?

Updated 9 October 2026 · 5 min read

! Rules

A DMARC record is a short line of text in your domain's DNS that tells Gmail, Yahoo and other mailboxes what to do with email that claims to be from your domain but fails authentication. It also asks them to send you daily reports, so you can see who is sending email as you.

What DMARC does

Anyone can type your address into the From line of an email. SPF and DKIM are the two checks that prove an email really came from you:

  • SPF is a DNS record that lists the servers allowed to send email for your domain.
  • DKIM is a digital signature that proves an email came from your domain and wasn't changed on the way.

DMARC sits on top of them. It answers two questions: did SPF or DKIM pass for the domain in the From address, and if not, what should happen to the email?

Gmail and Yahoo require a DMARC record from bulk senders. Even if you send less, a record protects your domain from being used in phishing, and the reports show you services you'd forgotten were sending as you.

Where the record lives

A DMARC record is a TXT record at _dmarc in front of your domain. For yourbusiness.com, that is _dmarc.yourbusiness.com. A domain must have exactly one: with two, receivers ignore both. A simple record looks like this:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com

Enter your domain to see the record you have now, what it asks receivers to do, and what to change.

This reads your public DNS only. To see whether your email actually passes, and where it lands, send a free test.

The parts of a record

Each part is a tag and a value, separated by semicolons.

TagExampleWhat it means
vv=DMARC1Marks this as a DMARC record. Always first.
pp=noneThe policy: what to do with email that fails.
ruarua=mailto:dmarc-reports@yourbusiness.comWhere to send daily summary reports.
pctpct=25Apply the policy to only part of failing email. Optional.
spsp=rejectA different policy for subdomains. Optional.
adkim, aspfadkim=sStrict alignment for DKIM or SPF. Optional; relaxed is the default.

The policy: none, quarantine or reject

  • p=none is monitoring mode. Receivers deliver email as they normally would and send you reports. Nothing changes for your email.
  • p=quarantine asks receivers to treat failing email as suspicious. In Gmail, Google Workspace and Yahoo that usually means the Spam folder.
  • p=reject asks receivers to refuse failing email outright. It never arrives.

With p=none, others can still send email pretending to be you. Quarantine and reject are what actually protect your domain.

Reports (rua)

The rua tag gives an address for aggregate reports. Mailbox providers send a daily summary of every email they saw using your domain: which servers sent it, and whether it passed SPF, DKIM and DMARC. Reports come as compressed XML files, so most people use a DMARC reporting service to read them. Google notes that large organizations can get hundreds or thousands of reports a day, so use a mailbox set aside for them, not your personal inbox.

Percentage (pct)

The pct tag applies your policy to only a share of failing email, for example pct=25 for a quarter. It was meant for a gradual rollout, and Google's rollout guide still uses it.

In practice, receivers applied values other than 0 and 100 inconsistently. The updated DMARC standard, RFC 9989, published in May 2026, drops pct and replaces it with a simple test flag, t=y or t=n. Many receivers still read pct today. Treat it as a rough brake, not an exact dial.

Alignment

Alignment is the heart of DMARC. Passing SPF or DKIM isn't enough on its own. The pass has to be for the same domain as your From address.

Say you send from hello@yourbusiness.com through an email service. If DKIM passes but the signature belongs to the service's own domain, DMARC fails. If the signature is for yourbusiness.com, DMARC passes. The same goes for SPF, which checks the hidden bounce address, not the From address you see.

By default alignment is relaxed, so a subdomain such as mail.yourbusiness.com counts as a match. Strict alignment (adkim=s or aspf=s) needs an exact match. Google notes that relaxed alignment usually gives enough protection.

This is why every service that sends as your domain, such as Mailchimp, HubSpot or Shopify, needs its own domain authentication. That setup is what makes its DKIM signature use your domain.

A safe rollout from p=none

Moving straight to p=reject can block your own invoices or newsletters if a service isn't set up yet. Go step by step:

  1. Set up SPF and DKIM first for every service that sends as your domain. Google recommends waiting at least 48 hours after that before adding DMARC.
  2. Start with monitoring:

    v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com

    Change the rua address to a mailbox you read.

  3. Read the reports for at least a week. Google's rollout guide suggests a week as the minimum. Look for genuine email that fails, and fix each service it comes from.
  4. Move to quarantine. Once reports show all your genuine email passing, change p=none to p=quarantine. To ease in, Google's guide starts with a small pct, such as pct=5, and raises it toward 100.
  5. Move to reject if you want full protection. When quarantine has run cleanly, change to p=reject.

Keep the rua address throughout, so you notice when a new tool starts sending as you.

How we check it

When you send one test email to your private test address, the report shows whether you have a DMARC record, what policy it sets, whether your email passed DMARC and through which check, and whether SPF and DKIM aligned with your From address. You get a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and the exact record to publish or change.

Checked against: Google Workspace Admin Help, Set up DMARC · Google Workspace Admin Help, Recommended DMARC rollout · Google Workspace Admin Help, Email sender guidelines · Yahoo Sender Hub, Sender best practices · RFC 7489, Domain-based Message Authentication, Reporting, and Conformance (DMARC) · RFC 9989, Domain-Based Message Authentication, Reporting, and Conformance (DMARC).

Questions people ask

Is p=none enough for Gmail and Yahoo?

Yes, for their bulk sender rules. Both accept p=none, as long as the record exists and your email passes DMARC through aligned SPF or DKIM. It doesn't stop others sending as your domain, though, so plan to move to p=quarantine.

Will adding a DMARC record stop my email being delivered?

Not with p=none. That policy only monitors, so nothing changes for your email. Delivery is only affected once you move to quarantine or reject.

Can I have more than one DMARC record?

No. A domain must have exactly one DMARC record at _dmarc. If there are two, receivers ignore both, as if you had none.

Who reads the rua reports?

You, or a service you choose. Reports arrive as compressed XML files, so many small businesses send them to a DMARC reporting service that turns them into charts. Use a mailbox set aside for them, as they can be numerous.

Does DMARC replace SPF and DKIM?

No. DMARC relies on them. Email passes DMARC only when SPF or DKIM passes for the same domain as your From address.