Email Authentication
DMARC record check
DMARC tells receivers what to do with email that fails SPF and DKIM, and sends you reports on who is sending as your domain.
Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.
What we look at
We read the TXT record at _dmarc.yourdomain and check that it exists, parses, what its policy is (none, quarantine or reject), and whether it asks for reports.
Why it matters to your business
DMARC is the record that actually stops someone sending email as you. SPF and DKIM only describe your mail; DMARC tells the world to reject what does not match. A domain with no DMARC, or with p=none, can be spoofed to your customers, and since 2024 Google and Yahoo require DMARC from anyone sending in volume.
How to fix it
- Start with a monitoring policy: publish v=DMARC1; p=none; rua=mailto:reports@yourdomain at _dmarc.yourdomain.
- Read the reports for a few weeks to find every legitimate sender, and fix their SPF and DKIM.
- Move to p=quarantine, then p=reject. At reject, forged mail in your name is refused before it reaches anyone.
If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.
Keep an eye on it
A one-off check tells you how things stand today. On Starter and up, DomainGuard re-checks the domains it watches every day and alerts you in the app when something important changes, so you hear about it before a customer does.
