Rankite
ServicesResultsToolsTeamAboutBlogCareersContactFree SEO Audit
Free tool

DMARC Record Generator: Build a Valid DNS TXT Record

Set your policy, reporting addresses and alignment mode, then copy a ready-to-publish DMARC record for your domain's DNS, free.

Home / Tools / DMARC Record Generator
Your DMARC DNS record
Record type
TXT
Host / name
_dmarc.example.com

Publish this as a TXT record at the host shown above. Start with p=none and watch your aggregate reports before moving to quarantine or reject.

Built by Rankite, the SEO team behind Swordfish AI's +400% revenue and Zluri's +45% organic growth. See the case studies

DMARC is the DNS record that tells other mail servers what to do when a message claims to be from your domain but fails SPF or DKIM checks. It is one of the simplest changes you can make to stop your domain from being used in phishing campaigns, and it takes about two minutes to generate and publish with this tool.

How DMARC fits with SPF and DKIM

SPF lists which mail servers are allowed to send email for your domain. DKIM signs outgoing mail so receivers can confirm it was not altered in transit. DMARC sits on top of both: it checks that a message passes at least one of them and that the passing domain aligns with the visible From address, then applies the policy you set. If SPF and DKIM are not already configured correctly, publishing a strict DMARC policy will cause your own legitimate mail to fail, so get those two working first.

Rolling out a policy safely

Start with p=none. This applies no enforcement at all, it only tells receiving servers to send you aggregate reports showing which sources are sending mail as your domain and whether they pass or fail. Review those reports for a few weeks, fix any legitimate sending source that is failing, then move to p=quarantine, which routes failing mail to spam, and eventually p=reject, which blocks it outright. The pct tag lets you apply a new policy to only a percentage of mail at first, so you can catch problems before they affect everything.

Where to publish the record

DMARC lives in DNS as a TXT record at the host _dmarc.yourdomain.com, never at the root domain. Log into your DNS provider, add a new TXT record, enter that host and paste the value this tool generates, then save. Propagation is usually fast, often under an hour, and you can confirm it is live with any DNS lookup tool once it has had time to spread.

Related articles

FAQ

DMARC Record Generator: questions, answered

What is a DMARC record and why do I need one?
DMARC is a DNS TXT record that tells receiving mail servers what to do with messages claiming to be from your domain that fail SPF or DKIM checks. Without one, your domain is easier to spoof for phishing, and without SPF and DKIM already set up, DMARC has nothing to enforce, since both need to be in place first.
What is the difference between p=none, quarantine and reject?
p=none takes no action and only sends you reports, which is the safest starting point while you monitor. p=quarantine tells receiving servers to send failing mail to spam. p=reject tells them to block it outright. Most domains start at none, watch the reports for a few weeks to confirm legitimate mail is not failing, then move to quarantine and eventually reject.
What does the pct tag do?
pct sets what percentage of failing messages the policy applies to, which lets you roll out enforcement gradually instead of all at once. Setting pct to 100, the default, applies the policy to every failing message. Starting lower, such as 10 or 25, and increasing it over time reduces the risk of a misconfiguration blocking legitimate mail.
Where do I publish the DMARC record?
Add it as a TXT record in your domain's DNS at the host _dmarc.yourdomain.com, using the exact record value this tool generates. Most DNS providers have a form for adding a TXT record where you paste the host and the value separately, then save and wait for propagation, which is usually under an hour.
Do I still need SPF and DKIM if I set up DMARC?
Yes. DMARC does not replace SPF or DKIM, it works on top of them. A message passes DMARC if it passes SPF or DKIM and the sending domain aligns with the header From address. Publishing DMARC without SPF or DKIM configured means every message will fail, which can quarantine or reject your own legitimate mail once you move past p=none.

More free tools

Let's grow

Ready to own page one?

Get a free, no-obligation SEO audit and a 30-minute strategy session. We'll show you exactly where the growth is hiding.

Book your free audit Explore services
Get in touch

Tell us about your project

Fill out the form and we'll get back to you within one business day. Prefer email? Write to us directly at contact@rankite.com.

Or copy our email and write to us directly: contact@rankite.com