Free tool

DMARC record generator

Build a valid DMARC policy for your domain, then roll it out from monitoring to enforcement without blocking your own mail.

Policy settings

Your DMARC TXT record

Host / name

_dmarc.example.com

Value

v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; adkim=r; aspf=r; fo=1

Authenticated sending, verified

Oitomail checks SPF, DKIM and DMARC for every sending domain you add and warns you before a policy change breaks delivery.

Start 7-day trial

A safe DMARC rollout

  1. Publish p=none with an rua address and collect reports for 2–4 weeks.
  2. Fix any legitimate sender that fails alignment (add it to SPF, or sign it with DKIM).
  3. Move to p=quarantine with pct=25, then raise to 100.
  4. Finish at p=reject — the only policy that fully stops spoofing of your domain.

Frequently asked questions

What is a DMARC record?

DMARC is a DNS TXT record at _dmarc.yourdomain.com that tells receiving servers what to do when a message fails SPF and DKIM alignment, and where to send reports.

Should I start with p=none?

Yes. Publish p=none first and read the aggregate reports for a few weeks to find every legitimate sender, then move to quarantine and finally reject.

What is the difference between relaxed and strict alignment?

Relaxed alignment allows subdomains to match the From domain; strict requires an exact match. Relaxed is the safe default for most senders.

Do I need DMARC for Gmail and Yahoo?

Yes. Bulk senders must publish at least a p=none DMARC record with aligned SPF or DKIM, or their mail is rejected or throttled.

Turn activity into retained revenue.

Start a 7-day trial with the full platform — no credit card. Or talk to us about a Platinum or Enterprise rollout.