Free DMARC Record Generator - Build DMARC TXT Records
DMARC (Domain-based Message Authentication, Reporting, and Conformance) protects your domain from email spoofing and phishing. Our free DMARC record generator helps you create a properly formatted DMARC TXT record by guiding you through policy selection (none, quarantine, reject), aggregate and forensic reporting URIs, SPF and DKIM alignment modes, subdomain policy, and percentage rollout - then outputs a copy-paste ready DNS record.
What This Tool Checks
Comprehensive analysis powered by Vysiro's scanning engines
Policy selection (none, quarantine, reject)
Aggregate reporting URI configuration (rua)
Forensic reporting URI configuration (ruf)
SPF alignment mode (relaxed or strict)
DKIM alignment mode (relaxed or strict)
Subdomain policy override (sp tag)
Percentage rollout control (pct tag)
Copy-paste ready TXT record output
How It Works
Get results in seconds with our automated scanning process
Choose your DMARC policy: none (monitor), quarantine (spam), or reject (block)
Enter an email address for aggregate report delivery (rua tag)
Optionally add a forensic report email address (ruf tag)
Select SPF and DKIM alignment modes (relaxed or strict)
Set an optional subdomain policy and rollout percentage
Copy the generated DMARC TXT record and add it to your DNS as _dmarc.yourdomain.com
Frequently Asked Questions
Everything you need to know about dmarc record generator
What is a DMARC record and why do I need one?
A DMARC record is a DNS TXT record published at _dmarc.yourdomain.com that tells receiving mail servers how to handle emails that fail SPF or DKIM checks. Without DMARC, attackers can freely spoof your domain to send phishing emails to your customers. DMARC is required by Google, Yahoo, and Apple for bulk senders.
Which DMARC policy should I start with?
Start with p=none to collect reports without affecting email delivery. Once you confirm all legitimate senders pass authentication, move to p=quarantine (sends failures to spam), then p=reject (blocks failures entirely). Vysiro recommends reaching p=reject within 90 days.
What are DMARC aggregate reports (rua)?
Aggregate reports are XML files sent daily by receiving mail servers that summarize authentication results for your domain. They show which IPs are sending email as your domain and whether those emails pass or fail SPF and DKIM. The rua tag specifies where to send these reports.
What is the difference between rua and ruf in DMARC?
The rua tag configures aggregate reports - daily XML summaries of authentication results. The ruf tag configures forensic reports - individual failure reports with message details. Forensic reports provide more detail but are less widely supported due to privacy concerns.
What does DMARC alignment mean and which mode should I use?
DMARC alignment checks whether the domain in the From header matches the domains used for SPF and DKIM. Relaxed alignment (default) allows subdomains to match, while strict requires an exact match. Use relaxed unless you have a specific reason to require strict matching.
Do I need a subdomain policy (sp tag)?
The sp tag lets you set a different DMARC policy for subdomains. If omitted, subdomains inherit the parent policy. Use sp=reject if your subdomains do not send email, even while your main domain is still at p=none. This prevents subdomain spoofing during your DMARC rollout.
Related Free Tools
Continue your domain security analysis
DMARC Checker
Analyze DMARC records and email authentication policies instantly.
Use toolSPF Generator
Build SPF TXT records with a visual mechanism builder, lookup counter, and validation.
Use toolDKIM Generator
Create DKIM DNS records with selector naming, key type selection, and record formatting.
Use toolTrustScore
Get an instant composite trust score (0-1000) across 29 security categories.
Use toolGo Beyond Free Checks
Get continuous monitoring, automated fixes, proof packs, and API access. Protect your domains with Vysiro's agentless attack-surface monitor.