How to Generate a DMARC Record
Enter your root organizational domain, choose the appropriate DMARC policy, configure the reporting and alignment options you need, then generate the TXT record for _dmarc.
Build a DMARC record against RFC 9989/9990/9991 (DMARCbis, published May 2026). Check live DNS evidence first, then generate a policy with an evidence-aware view of what could go wrong if you do — or do not — change it.
Enter the domain people receive email from. This queries _dmarc.yourdomain.com and the root domain's SPF via Cloudflare's public DNS-over-HTTPS resolver.
Each control maps to a DMARC tag. Defaults are omitted where the protocol provides a default, keeping the generated record shorter and easier to audit.
Publish this as a TXT record. The preview updates as you change settings.
Evidence first, interpretation second. This decision aid reports signals from the live check and selected settings and explicitly marks what is still unknown.
Use these three practical workflows to generate a DMARC record, check your existing DNS configuration, and move from monitoring toward enforcement safely.
Enter your root organizational domain, choose the appropriate DMARC policy, configure the reporting and alignment options you need, then generate the TXT record for _dmarc.
Check the live DMARC TXT record and review its policy, reporting, and alignment settings. Also verify which legitimate services are authorized to send mail for your domain before making changes.
Start by collecting and reviewing DMARC reports, fix SPF or DKIM authentication and alignment problems, then consider p=quarantine before moving to p=reject when legitimate mail is consistently authenticated.