DMARC checker, policy explained.
Reads a domain's DMARC policy, says what receivers will do with mail that fails, and checks the report addresses really receive reports.
What DMARC decides.
DMARC ties SPF and DKIM to the address people see in the From line. A message passes when SPF or DKIM passes for a domain that matches the From domain. The policy at _dmarc.example.com tells receivers what to do with mail that fails, and where to send reports about it.
The tags.
p: the policy.noneonly reports,quarantinesends failing mail to spam,rejectrefuses it.sp: the policy for subdomains, when it differs.rua: where daily summary reports go.ruf: where reports on single failures go; few receivers send them.adkimandaspf:r(relaxed, the default) lets a subdomain match its parent;s(strict) does not.pct: the share of failing mail the policy applies to.
Reports sent to another domain.
If rua points to an address on another domain, such as a DMARC reporting service, that domain must publish a record agreeing to receive your reports. Without it, receivers send nothing. This page checks that record for every outside address.
A safe path to reject.
Start with p=none and a report address, read the reports for a few weeks to find every service that sends as you, fix their SPF and DKIM, then move to quarantine and finally reject.
Questions people ask.
What is DMARC?
A policy published at _dmarc on a domain that tells receivers what to do with mail failing SPF and DKIM, and where to send reports about it.
Which DMARC policy should I use?
Start with p=none and a report address, then move to quarantine and finally reject once all your real mail passes.
Why am I not receiving DMARC reports?
Check the rua address. If it is on another domain, that domain must publish a record agreeing to receive your reports, or receivers send none.
Does DMARC apply to subdomains?
Yes. A subdomain without its own record uses the policy of its organizational domain, or its sp= policy when one is set.
Hivex index
Short names, still free to register.
Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.
From code, or an AI assistant.
Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.
More Email tools
- Email deliverability checkerMX, SPF, DKIM, DMARC, MTA-STS, TLS reporting and BIMI in one report.
- SPF checkerEvery include followed, the 10-lookup limit counted, mistakes named.
- DKIM checkerFinds keys at common selectors and checks their type and size.
- SPF generatorPick your mail services, get one record that stays under 10 lookups.
- DMARC generatorPolicy, reports and alignment, with a safe rollout path.
- MTA-STS checkerPolicy record, policy file, MX match and TLS reports.
- BIMI checkerRecord, DMARC, SVG logo and VMC or CMC, with a preview.
- Email blacklist checkerAn IP or a domain against live email blocklists.
- Email header analyzerWho sent it, SPF, DKIM, DMARC and every hop, in your browser.
- SMTP testGreeting, STARTTLS and sign-in methods on 587 and 465.
- Domain checkerIs a name free to register? Checked live on any extension.
Sources
By Hivex. Updated 10 October 2026. Lookups run live through Cloudflare's public resolver and are kept for at most five minutes.