The XiaTools DMARC Checker is a free online utility designed to query and validate the Domain-based Message Authentication, Reporting, and Conformance (DMARC) record of any given domain. By entering your domain name, you can instantly inspect your current email security configuration, policy enforcement level, and reporting destinations.
What is it
A DMARC record is a TXT record published in your domain's DNS settings that tells receiving mail servers how to handle emails sent from your domain. It works in tandem with Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) to verify that an incoming message genuinely originates from your organization. When an email fails SPF or DKIM checks, DMARC instructs the receiving server on whether to deliver, quarantine, or completely reject the message based on your specified policy. Furthermore, DMARC provides a mechanism for receiving servers to send forensic and aggregate reports back to you, detailing traffic sources and potential spoofing attempts.
Why it matters
Implementing DMARC is crucial for protecting your brand's reputation and preventing malicious actors from sending phishing emails using your domain name. Without a strict DMARC policy, cybercriminals can easily forge your sender address, deceiving customers, partners, and employees into trusting fraudulent messages. Internet service providers increasingly flag or block unauthenticated emails, meaning a missing or misconfigured DMARC record can severely damage your email deliverability rates. By monitoring DMARC aggregate reports, you gain complete visibility into your email ecosystem, allowing you to identify all legitimate sending services and detect unauthorized infrastructure attempting to abuse your domain.
How to use this tool
- Navigate to the XiaTools DMARC Checker page.
- Locate the input field designated for the domain name.
- Enter your domain name in the box, omitting any prefixes like "http://" or "https://" (for example,
example.com). - Press the Check button to initiate a live DNS query for your domain's DMARC record.
- Review the parsed output displayed on the screen to analyze your current configuration.
How to read the results
When you check a domain like example.com, our tool queries the DNS for the TXT record located at _dmarc.example.com and breaks down each tag. Here is an explanation of the values and settings you will see in a typical realistic output:
- Record Status: Indicates whether a valid DMARC record was successfully found in the DNS. For
example.com, it will show "Valid" or "Not Found". - Raw Record: Displays the exact TXT string retrieved from your DNS, such as
v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com; pct=100;. - Protocol Version (
v): Always set toDMARC1, indicating the version of the DMARC specification being used. - Policy (
p): Specifies the instruction for receiving servers when email fails authentication. A value ofnonemeans emails are monitored only and delivered normally;quarantinesends failing emails to the spam or junk folder;rejectblocks failing emails entirely at the server level. - Subdomain Policy (
sp): Defines the policy specifically for subdomains (e.g.,sub.example.com). If omitted, subdomains inherit the main policy (p). - Aggregate Reporting Address (
rua): The email address where XML-formatted daily summary reports are sent, formatted as a mailto URI (e.g.,mailto:dmarc-reports@example.com). - Forensic Reporting Address (
ruf): The email address where individual failure reports are sent in real-time when an email fails authentication. - Percentage (
pct): Determines the percentage of messages filtered by the DMARC policy. If set to50, only half of the failing emails are subjected to theppolicy. If omitted, it defaults to100. - Alignment Mode (
aspfandadkim): Controls identifier alignment for SPF and DKIM.rstands for relaxed alignment (matching the organizational domain), whilesstands for strict alignment (requiring an exact match of the domain name).
Common problems and how to fix them
Missing DMARC Record
If the tool reports that no DMARC record exists, you must create a TXT record in your DNS zone manager. Create a new TXT record with the host name _dmarc and a basic monitoring value to start safely.
_dmarc.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com;"
Syntax and Typo Errors
DMARC records are strictly parsed, and a simple typo in a tag name will cause the record to be ignored by receiving servers. Ensure all tags are lowercase, separated by semicolons, and prefixed with v=DMARC1;.
Invalid Reporting URIs
If your rua or ruf addresses point to an external domain that has not authorized your reports, the reports will fail to deliver. Ensure external domains include a DMARC external destination verification TXT record in their own DNS.
Best practices
Start your DMARC journey conservatively by setting your policy to p=none alongside an aggregate reporting address (rua). Monitor these reports for several weeks to identify all legitimate third-party senders, such as marketing platforms and helpdesk software, ensuring their SPF and DKIM signatures are correctly aligned. Once you are confident that all legitimate mail is authenticating successfully, incrementally move your policy to p=quarantine, and finally enforce full protection with p=reject. Regularly review your aggregate reports to catch unauthorized sending attempts and maintain optimal email deliverability.