Skip to content
Hivex tools · EmailFree · No account

DMARC record generator.

Choose a policy and where reports go, and get a DMARC record to paste into your DNS, with a safe path from monitoring to reject.

Your domain

Optional: only used to show the exact name the record goes on.

What receivers do with mail that fails
Where reports go

Daily summary reports are the useful ones. Single-failure reports are optional, and few receivers send them.

More settings
Subdomains
Share of failing mail the policy applies to
Alignment

Relaxed lets mail from a subdomain count for the domain. Strict needs an exact match.

Nothing is saved. The record is built on the page.

Where the record goes.

Add the record as a TXT record at _dmarc on your domain (the full name is _dmarc.example.com). One record per domain; it covers subdomains too unless they have their own.

Roll out in three steps.

  • p=none with a report address: nothing changes for your mail, and you learn who sends as you.
  • p=quarantine once SPF and DKIM pass for all your real mail: failing mail goes to spam.
  • p=reject: failing mail is refused, and your domain is hard to fake.

Reports to another domain.

Sending reports to a reporting service on its own domain? That service must publish a record that accepts reports for your domain. Most do it when you sign up; the DMARC checker confirms it.

Questions people ask.

How do I create a DMARC record?

Choose a policy and a report address, then add the record as a TXT record at _dmarc on your domain.

What should my first DMARC policy be?

p=none with a report address, so nothing changes while you learn who sends mail as your domain.

What is rua in DMARC?

The address that receives daily summary reports about mail claiming to come from your domain.

What is the difference between quarantine and reject?

Quarantine asks receivers to put failing mail in spam; reject asks them to refuse it.

Hivex index

Short names, still free to register.

Starting something new? Hivex keeps a live index of short, brandable .si names nobody has claimed yet, each checked with the registry.

Browse free names

From code, or an AI assistant.

Hivex's free JSON API and MCP server check domains, DNS and registration records from your own code or from AI assistants that speak MCP. No key needed.

The API guideThe MCP serverOpenAPI schema

Sources

  1. RFC 7489: DMARC
  2. Google: Email sender guidelines (since 1 February 2024)

By Hivex. Updated 10 October 2026. Records are built on the page; nothing you type is saved.