Routelearn.net
Security Tools

DMARC Checker

Look up a domain's DMARC policy and see exactly what it tells mail servers to do.

How it works

The tool fetches the TXT record at _dmarc.<domain> live over DNS and parses every tag in it. Then it flags things worth a second look, like a policy of none or no report address at all.

FAQ

What is DMARC?
DMARC stands for Domain-based Message Authentication, Reporting & Conformance. It's a DNS TXT record, published at _dmarc.<domain>, that tells receiving mail servers what to do with messages that fail SPF and/or DKIM, and where to send reports about them. DMARC is what actually makes SPF and DKIM enforceable, instead of just advisory.
What's the difference between none, quarantine, and reject?
These are the enforcement policies, from weakest to strongest. None takes no action and only sends reports. Quarantine asks receivers to treat failing mail as suspicious, usually by routing it to spam. Reject asks receivers to refuse the message outright.
Why does "p=none" show up as worth a look?
It's not wrong. It's the normal, safe starting point while a domain owner reviews aggregate reports before tightening enforcement. The checker flags it only as a reminder that, as configured, DMARC isn't blocking anything yet.
Does DMARC replace SPF and DKIM?
No, it sits on top of them. DMARC doesn't authenticate anything itself. It defines what "pass" means (SPF or DKIM aligned with the domain in the From: address), and what to do when a message fails that alignment.

Related tools