DMARC record generator
Build a valid DMARC policy for your domain, then roll it out from monitoring to enforcement without blocking your own mail.
Policy settings
Your DMARC TXT record
Host / name
_dmarc.example.comValue
v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r; fo=1Authenticated sending, verified
Oitomail checks SPF, DKIM and DMARC for every sending domain you add and warns you before a policy change breaks delivery.
Start 7-day trialA safe DMARC rollout
- Publish
p=nonewith anruaaddress and collect reports for 2–4 weeks. - Fix any legitimate sender that fails alignment (add it to SPF, or sign it with DKIM).
- Move to
p=quarantinewithpct=25, then raise to 100. - Finish at
p=reject— the only policy that fully stops spoofing of your domain.
Frequently asked questions
What is a DMARC record?
DMARC is a DNS TXT record at _dmarc.yourdomain.com that tells receiving servers what to do when a message fails SPF and DKIM alignment, and where to send reports.
Should I start with p=none?
Yes. Publish p=none first and read the aggregate reports for a few weeks to find every legitimate sender, then move to quarantine and finally reject.
What is the difference between relaxed and strict alignment?
Relaxed alignment allows subdomains to match the From domain; strict requires an exact match. Relaxed is the safe default for most senders.
Do I need DMARC for Gmail and Yahoo?
Yes. Bulk senders must publish at least a p=none DMARC record with aligned SPF or DKIM, or their mail is rejected or throttled.
Turn activity into retained revenue.
Start a 7-day trial with the full platform — no credit card. Or talk to us about a Platinum or Enterprise rollout.