DMARC Lookup

Check a domain's DMARC record: policy for unauthenticated e-mails, reports, alignment and common configuration mistakes.

About this tool

DMARC Lookup finds the DMARC record of a domain and explains each of its tags. DMARC tells receiving mail servers what to do with e-mails that fail the SPF and DKIM checks - deliver them, move them to spam or reject them - and where to send reports about them. The tool validates the syntax, fills in default values, warns about a weak policy, missing reports or unauthorized external report addresses, and suggests a starter record when none exists.

Glossary

DMARC
A DNS rule that tells receivers what to do with e-mails pretending to come from the domain that fail both SPF and DKIM, and where to send reports.
SPF
A TXT record listing the servers allowed to send e-mail for the domain. A domain may have only one and it must not require more than 10 DNS lookups.
DKIM
A digital signature of an e-mail. The public key is in DNS (selector._domainkey.example.com) and the receiver uses it to verify that an authorized server sent the message and nobody changed it.
Alignment
DMARC requires the domain verified by SPF or DKIM to match the domain in the From field. Relaxed alignment accepts a subdomain, strict does not.
Policy none, quarantine, reject
none only monitors, quarantine moves failing e-mails to spam, reject refuses them. The usual path is to start with none and move to reject step by step based on reports.
rua and ruf reports
Aggregate reports (rua) arrive once a day in XML and show which servers sent mail for the domain. ruf reports describe individual failing messages.
BIMI
A record pointing to a brand logo in SVG format. Gmail, Apple Mail and Yahoo show it next to e-mails from a domain with DMARC quarantine or reject.
MTA-STS
A policy that enforces encrypted (TLS) delivery of e-mail to the domain's mail servers and prevents an attacker from stripping encryption.
TLS-RPT
A _smtp._tls record with an address where sending servers deliver reports about problems with encrypted mail delivery.
SMTP
The protocol mail servers use to pass e-mails to each other, by default on port 25. The STARTTLS command turns on encryption.

How to use

  1. 1Enter a domain (example.com) or an e-mail address.
  2. 2Click Check DMARC or press Enter.
  3. 3Review the record and the table of tags with explanations.
  4. 4Go through the findings - they warn about a weak policy or missing reports.
  5. 5No record? Copy the suggested record and add it to the domain's DNS.

Specifications and limits

The record is read from the TXT record at _dmarc.example.com via the public resolvers of Cloudflare (1.1.1.1) and Google (8.8.8.8). If a subdomain has no record of its own, parent domains are checked step by step. Validation follows RFC 7489 and also recognizes newer DMARCbis tags (np, psd, t). For report addresses outside the domain the authorization record is verified. You can also enter an e-mail address, the domain is taken from it. The limit is 20 queries per minute.