Free tool · Deliverability

A DMARC record
you understand.

Build a valid DMARC record, with every tag explained in plain English.

Runs entirely in your browser. No signup, nothing stored.
DNS record typeTXT
Host / name_dmarc.yourbrand.com
Valuev=DMARC1; p=none; adkim=r; aspf=r; t=n
Add rua to receive reports.
How this works

The method, not the marketing.

DMARC tells mailbox providers what to do when a message claiming to be from your domain fails SPF and DKIM alignment — and where to send reports about it. The record is a single TXT entry at _dmarc.yourdomain.com.

This generator follows RFC 9989, published in 2026, which obsoletes RFC 7489. Two changes matter: the pct tag has been removed and replaced by t (test mode), and a new np tag sets policy for subdomains that do not exist. Most generators still emit pct — records using it remain widely honoured, but it is no longer part of the standard.

Start at p=none with reporting enabled. That changes nothing about delivery but starts the reports flowing, so you can find legitimate mail that is failing before you enforce. Move to quarantine, then reject, once the reports are clean — or set t=y to publish an enforcing policy that receivers deliberately do not act on yet.

Everything runs in your browser. No domain is looked up and nothing is stored.

Bring your provider.
Keep your brands distinct.
Start today.

Set up your first workspace, connect a provider, and publish a workflow — free, in test mode, before you pay a thing.