Free Tool

Generate a valid DMARC record in minutes

Choose how strict to be with mail that fails SPF or DKIM, where reports should go, and copy the finished record straight into your DNS — every option explained as you go.

DMARC tells receiving mail servers what to do with messages that fail SPF or DKIM — and where to send reports about them. It only works once SPF and/or DKIM are already set up, so if you haven't generated an SPF record yet, start there first.

Leave at 100 once you trust your setup. A lower number applies your policy to only that percentage of failing mail (chosen at random) and lets the rest through untouched — useful for a gradual rollout, not something to leave permanently.

Strongly recommended. Once a day, mail providers send a summary here of everyone who sent mail claiming to be from your domain — the only real way to see who's sending on your behalf, including services you may have forgotten about. Use an inbox you actually check, or a dedicated one like dmarc-reports@yourdomain.com.

Sends a copy of each individual message that fails, not just a daily summary — most mail providers ignore this or send very little, and it can include personal data from the failing message, so most domains leave this empty and rely on the aggregate reports above instead.

Free tool, provided without warranty or professional liability on our part — by using it, you agree we accept no liability for the result. Need a guarantee? Hire a qualified professional instead. Details in the Free Tools section of our Terms of Service.

How to add this to your domain

  1. 1

    Copy the DMARC record above.

  2. 2

    Log in to your domain's DNS provider (your registrar or DNS host).

  3. 3

    Create a new TXT record with the host/name set to "_dmarc" — for example _dmarc.yourdomain.com, not the bare domain.

  4. 4

    Paste the copied record as the value, and save.

  5. 5

    Give it time to propagate, then verify it. If this is your first DMARC record, keep the policy at "none" for a few weeks and review your reports before moving to quarantine or reject.

If your domain already has a DMARC record, don't add a second one — a domain can only have one. Replace your existing record instead.

Verify your SPF, DKIM, and DMARC setup with our free checker →

DMARC stops lookalike spoofing — not a hijacked real account

Even perfect SPF, DKIM, and DMARC enforcement can't protect an attachment sent from a genuine account that's been compromised. Adlerwacht adds a passkey check on top, so the file itself stays protected either way.

Try Adlerwacht free for 30 days