Email Security

Free DMARC Record Checker

Check whether your domain publishes a DMARC record, what policy it enforces, and whether anyone can send email pretending to be you.

Free · No signup · Runs a full siteIQ audit on your URL

Without DMARC, anyone in the world can send email that appears to come from your domain. Email has no built-in sender verification — the From field is just text, and a receiving server with no DMARC policy to consult will usually deliver a forgery anyway.

This check reads your domain's DNS and reports whether a DMARC record exists, which policy it enforces, and whether aggregate reporting is set up. It is free, needs no signup, and works on any domain — including ones you do not own.

What this tool checks

DMARC record present

Whether a policy exists at _dmarc.yourdomain.com at all — most domains have none.

Policy strength

p=none only monitors. p=quarantine sends failures to spam. p=reject blocks them outright.

Reporting address

Whether rua= is set, which is what gives you visibility into who is sending as you.

SPF alignment

Whether a valid SPF record exists for DMARC to evaluate against.

DKIM signing

Whether DKIM is configured, so DMARC has a second signal to check.

MX records

Which mail servers actually receive mail for the domain.

Why it matters

Invoice fraud almost always starts here. An attacker sends a convincing email from your domain to your customer, changes the bank details, and the customer pays them instead of you. DMARC at p=reject is what stops that message being delivered.

Gmail, Yahoo and Microsoft now require authentication for anyone sending meaningful volume. A missing DMARC record increasingly means your legitimate mail lands in spam too — so this is a deliverability problem as well as a security one.

How to read your results

  • No DMARC record at all is the most common and most serious result. Start at p=none with a rua address so you collect data without changing mail flow.
  • p=none is monitoring only — it enforces nothing. If you have been sitting there for months, it is time to move to quarantine.
  • No rua address means you are getting no reports, so you will never learn which legitimate services are failing before you tighten the policy.
  • Never jump straight to p=reject. Read reports for two to four weeks first, or you will silently block your own invoicing system.

Frequently asked questions

What is a DMARC record?

A TXT record published at _dmarc.yourdomain.com that tells receiving mail servers what to do with messages claiming to be from you that fail SPF and DKIM checks — deliver, quarantine or reject.

What does p=none actually do?

Nothing to your mail flow. It only asks receivers to send you reports. It is the correct place to start, but it protects nobody — many domains get stuck there for years thinking they are covered.

Do I need SPF and DKIM as well?

Yes. DMARC does not check anything itself — it decides what to do when SPF and DKIM fail. Without at least one of them configured and aligned, DMARC has nothing to act on.

Can I check a domain I don't own?

Yes. DMARC records are public DNS entries, so this works on any domain — useful for checking a supplier or a client before an engagement.

How long until DNS changes take effect?

Usually minutes to a few hours, depending on your record's TTL. Re-run the check after updating to confirm the new value is live.

Read next

SPF, DKIM and DMARC Explained (And Why Your Email Goes to Spam)

More free tools

Want the full picture?

Run a complete siteIQ audit — security, performance, SEO, accessibility and infrastructure — 65+ checks across 8 categories, in one report.

Free · No signup · Runs a full siteIQ audit on your URL