Email & SMTP
Check DMARC Configuration
Find out what your current DMARC policy is actually doing and who is sending mail using your domain.
The Problem
You might have a DMARC record, but no idea if it's set to none, quarantine or reject, who the rua reports are going to (if anyone), or whether it's actually protecting you from spoofing at all.
About this problem
Plenty of domains have a DMARC record that was set up once and never revisited — the policy might still be at the loosest setting, the reporting address might point to an inbox nobody checks any more, or the record might have a syntax issue that makes it ineffective without anyone noticing.
This check is usually requested when someone inherits a domain's email setup, before making changes to DMARC, or simply because they've never actually confirmed what their current record does in practice.
What's Included
- Looking up and decoding your current DMARC record
- Explaining exactly what the current policy does in practice
- Checking whether aggregate reports are configured and reachable
- A short written summary of your current exposure to spoofing
What's NOT Included
- Publishing or changing the DMARC record (see "Configure DMARC")
- Reading or summarising historical DMARC aggregate reports
- Setting up SPF/DKIM if they're missing
How It Works
- Retrieve and decode the current DMARC record from the _dmarc subdomain.
- Translate the policy (p=), alignment modes, and percentage rollout into plain English.
- Check whether the rua (aggregate report) address is valid and actually reachable.
- Verify the record's syntax is valid and will be interpreted correctly by mail servers.
- Summarise your current real-world exposure to spoofing based on what's actually configured.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- How do I check my current DMARC record?
- Look up the TXT record at _dmarc.yourdomain.com — the v=DMARC1 line shows the policy and settings, but correctly interpreting what it actually does (especially alignment modes and percentage rollout) takes more than reading it at a glance.
- What does p=none mean in DMARC?
- It means the domain is only monitoring — mail failing checks isn't blocked or sent to spam, it's just reported in aggregate reports, which is a safe starting point but offers no protection against spoofing yet.
- Why am I not receiving DMARC reports?
- Usually because the rua address in the record is wrong, unmonitored, or was never actually set up to receive and parse the reports properly.
- Is having any DMARC record enough?
- It depends what it's set to — p=none provides visibility but no actual protection; only quarantine or reject policies actively stop spoofed mail from reaching inboxes.
- Can I check DMARC without owning the domain?
- DNS records are publicly queryable, so basic lookups work for any domain, but acting on findings (like requesting changes) requires access to that domain's DNS.
- Does a DMARC check make any changes?
- No, this is read-only — it tells you what's currently configured. Changing the policy is a separate, explicitly scoped service.