LeadHaste
← Back to Free Tools

Free tool · Deliverability DMARC Checker

Look up your domain's DMARC record and understand exactly what it does. We read your policy, confirm reporting is configured, and surface the gaps that let spoofers through and push email to spam.

01The tool
02Guide

How to read your DMARC results

DMARC is the policy layer that makes SPF and DKIM enforceable. It tells receiving servers what to do with mail that fails authentication and sends you reports on everyone sending as your domain. Since Google and Yahoo's 2024 sender requirements, it's no longer optional for anyone sending at volume.

Your policy level

The p= tag is the heart of the record. p=none monitors only, useful at first, but it protects nothing. p=quarantine diverts failing mail to spam, and p=reject blocks it. The goal is to climb from none to reject as your reports confirm every legitimate sender passes.

Reporting address

A rua= tag tells receivers where to send aggregate reports. Without it, you're flying blind. You can't see which services send as your domain or whether they pass authentication. We flag a missing reporting address because it's the single most useful thing DMARC gives you during setup.

Enforcement percentage

A pct= below 100 applies your policy to only a fraction of mail. It can be handy when rolling out a strict policy gradually, but most domains should run at 100 for full coverage.

DMARC depends on SPF and DKIM

A DMARC policy only does its job if SPF and DKIM are correctly configured underneath it. Check both with the SPF checker and DKIM checker, or run the combined deliverability test to see all three at once.

We set DMARC to enforcement and monitor the reports across every sending domain we manage. See how our cold email infrastructure is built, or read the full SPF, DKIM & DMARC guide for cold email.

03FAQ

Frequently asked questions

What is a DMARC record?

DMARC (Domain-based Message Authentication, Reporting & Conformance) is a DNS TXT record published at _dmarc.yourdomain.com. It ties SPF and DKIM together by telling receiving servers what to do when a message fails authentication: do nothing, quarantine it, or reject it, and where to send reports about who's sending mail as your domain.

How do I check my DMARC record?

Enter your domain above. We look up the TXT record at _dmarc.yourdomain.com, confirm it starts with "v=DMARC1", and parse your policy and reporting tags. We flag the issues that matter most: a missing record, a "p=none" policy that offers no protection, a missing reporting address, and a pct value below 100.

What does p=none, p=quarantine, and p=reject mean?

These are your DMARC policy levels. "p=none" only monitors: failing mail is still delivered, but you get reports. "p=quarantine" sends failing mail to the spam folder. "p=reject" blocks it outright. Start at none to gather data, then progress to quarantine and finally reject as you confirm your legitimate senders all pass.

Is p=none safe to leave in place?

It's a fine starting point but a poor destination. "p=none" gives you visibility without any enforcement, so spoofers can still impersonate your domain and Gmail/Yahoo bulk-sender requirements aren't fully satisfied. Use the reports it generates to confirm your real senders pass, then move to quarantine and reject.

Do I need DMARC to send cold email?

Effectively, yes. Since Google and Yahoo's 2024 bulk-sender rules, domains sending volume without DMARC face throttling and spam placement. For outbound specifically, DMARC plus correctly configured SPF and DKIM is the baseline. Without it, even well-written emails struggle to reach the inbox.

Want us to build your outbound system?

Skip the DIY. We'll orchestrate your entire outbound operation, on infrastructure registered in your name from day one.

Book your free ICP review →