SendCanyon

Free DMARC Record Generator.

Build one valid DMARC record, check the one you publish now and see whether your reports will actually arrive.

AI-powered. AI explains your record and each finding in plain English and drafts your rollout plan; our parser decides every result.

Advanced: DKIM Selector
Policy For Mail That Fails DMARC

Monitor only. Mail is delivered as usual and reports are sent.

Send Aggregate Reports To

Daily summaries of who sent mail as your domain.

Subdomains, Alignment And Failure Reports
Alignment
Send Failure Reports To

Optional. Some receivers never send them, and they can contain message content.

Send A Failure Report When (fo)

Your DMARC Record

Type
TXT
Host
_dmarc
TTL
3600

v=DMARC1; p=none

Enter _dmarc as the host. If your DNS panel shows your domain after the field, do not type it again.

What Each Tag Does
v=DMARC1
Marks this as a DMARC record. Always first.
p=none
What receivers should do with mail from your domain that fails DMARC.

How it works

One Record, Checked Before You Publish It

Three steps from an empty field to a record receivers apply.

  1. 01

    Check Your Domain

    We read the DMARC record your domain publishes now, or the parent record that covers it, along with SPF, DKIM and where your reports go.

  2. 02

    Choose A Policy

    Pick none, quarantine or reject and add a report address. The record updates as you go, in the order every receiver reads.

  3. 03

    Publish And Verify

    Add one TXT record at _dmarc, then verify it. We ask your own name servers, so you see what you published straight away.

What we check

Every Rule A Receiver Applies

Each check follows RFC 9989, the 2026 DMARC standard, and RFC 7489, which many receivers still follow.

  • Record Syntax

    A record with a wrong version, a missing policy or a second copy is ignored.

    • v=DMARC1 first, exactly
    • A valid p, sp and np
    • One record per host
    • Retired pct, rf and ri
  • Reports

    Reports to another domain are dropped unless that domain agrees to receive them.

    • Valid mailto addresses
    • External destinations authorised
    • Failure report options
    • Size limits that are ignored
  • Coverage

    A subdomain with no record of its own is covered by a parent's.

    • Inherited policy
    • Subdomain and non-existent subdomain policy
    • Records published at the wrong host
  • Readiness

    Enforcing before SPF and DKIM pass blocks your own mail.

    • SPF record valid
    • DKIM key published
    • Gmail, Yahoo and Outlook bulk sender rules
    • Rollout from none to reject

AI-powered

Plain-English Answers, Checked By The Parser

The DMARC parser decides every result. SpirenAI, SendCanyon's AI, only explains what it found and writes each rollout step from your domain's live SPF, DKIM and report checks. Anything it says that the parser cannot back is dropped.

  • Explains your current record and each finding in plain words
  • Turns your live SPF, DKIM and report checks into a rollout plan
  • Uses only records, domains and numbers from the checked result
  • Never shortens the minimum time at each stage

DMARC Record Questions

What DMARC does, how to publish it, and how to move from monitoring to reject.

A DMARC record is a TXT record at _dmarc.yourdomain.com that tells receiving mail servers what to do with mail that uses your domain but fails authentication, and where to send reports about it. It starts with v=DMARC1, followed by a policy of none, quarantine or reject and usually a report address in rua. Mail passes DMARC when SPF or DKIM passes for a domain that matches the one in the From address.

DMARC Is One Of Three Records.

SendCanyon checks SPF, DKIM and DMARC on every sending domain before a campaign leaves, and re-checks them every six hours.

Start free trialBook a demo

14-day free trial. No card required.