Developer · Validator
DMARC record validator.
Paste a DMARC TXT record and check each tag against RFC 7489, with a plain-language reading of what it asks receivers to do. Runs in your browser; nothing is sent anywhere and no DNS lookup is made.
Input
Result
Paste a record and press Validate.
The DMARC tags this tool checks
v (required): must be exactly DMARC1 and must be the first tag. If it is missing or different, receivers ignore the whole record.
p (required for a policy record): none, quarantine or reject, and it must come second. It applies to the domain and, unless sp is set, to its subdomains.
sp: the same three values, for subdomains only. If absent, p applies to subdomains.
rua and ruf: comma-separated report addresses as URIs, for example mailto:[email protected]. A URI may end with ! and a size limit such as !10m (k, m, g or t; powers of two). Receivers must support mailto:. Without ruf, no failure reports are requested.
adkim and aspf: r (relaxed, the default) or s (strict) alignment for DKIM and SPF.
pct: a whole number from 0 to 100 (default 100), the share of mail the policy is requested for.
ri: seconds between aggregate reports, a 32-bit unsigned integer (default 86400, one day).
fo: colon-separated 0, 1, d, s (default 0); ignored without ruf. rf: report format, only afrf is defined.
Whitespace around = and ; is allowed. Unknown tags are ignored by receivers, so this tool lists them as a note rather than an error.
Source: RFC 7489, section 6.3 (General Record Format) and section 6.4 (Formal Definition).
Frequently asked questions
What is a minimal valid DMARC record?
v=DMARC1; p=none is the shortest record that follows the format. Most people add a rua=mailto: address so they receive aggregate reports.
Why does the p tag have to be second?
RFC 7489 section 6.3 says the v and p tags must be present and appear in that order in a policy record. Other tags may follow in any order.
Does this generate a record?
No. Use the example as a starting point and edit it. The tool only checks what you paste.
Does a valid result mean my DMARC is working?
No. It only means the text follows the RFC 7489 format. This tool cannot look up DNS, so it cannot tell whether the record is published at _dmarc.yourdomain, or whether SPF and DKIM align.
Syntax check only
This tool checks record format against RFC 7489 only. It does not query DNS, does not verify report addresses accept reports, and cannot confirm how any mail receiver will act on the record.