DMARC Record Generator
FreeBuild a DMARC DNS record from plain-language fields, with staged rollout presets and a live enforcement-level indicator.
Runs entirely in your browser. Nothing is sent anywhere, and no DNS lookup is performed.
Rollout Presets
DMARC is usually rolled out in stages. Pick a stage to prefill the fields below, then adjust as needed.
Basics
Comma-separated. Daily summary reports of pass/fail counts, this is how you see DMARC working.
Per-message failure reports with headers attached. Most mailbox providers ignore this now, few send it.
Advanced (alignment, failure reporting, interval)
Leave blank for the default (86400 = once a day). Most providers send daily regardless.
Recent Activity
Visible to everyone. Last 20 uses across all visitors, newest first.
p=none, pct=100%
1 hour ago
What this tool does
This tool builds a DMARC DNS TXT record from plain-language fields, covering every tag in the standard: policy, subdomain policy, report addresses, rollout percentage, alignment modes, and failure-reporting options. It also shows a live enforcement-level indicator and ships with three one-click rollout presets (monitor, partial enforcement, full enforcement) so you can move through a safe staged deployment instead of guessing at the syntax.
How It Works
A DMARC record is a single DNS TXT record published at _dmarc.yourdomain.com, made of semicolon-separated tag=value pairs starting with v=DMARC1. The policy tag (p=) tells receiving mail servers what to do with mail that fails both SPF and DKIM alignment: none just monitors, quarantine sends it to spam, and reject blocks it outright. This tool assembles those tags in the conventional order, omits tags that are already at their RFC-default value to keep the record clean, and wraps every report address in rua= or ruf= with the required mailto: prefix automatically.
Problems it solves
- Getting the exact DMARC TXT record syntax right without memorizing every tag name.
- Planning a safe, staged rollout instead of jumping straight to a policy that could block legitimate mail.
- Understanding what each tag actually changes, in plain language, not just RFC jargon.
- Catching a common mistake before publishing, like setting a strict policy with no reporting address configured.
Frequently asked questions
›Do I need SPF and DKIM before setting up DMARC?
Yes. DMARC checks whether a message passes SPF or DKIM (or both) AND whether the domain in those checks "aligns" with the domain in the visible From address. Without at least one of SPF or DKIM already configured and passing for your sending sources, every message will fail DMARC regardless of what policy you set.
›Why does the preset start at p=none instead of p=reject?
Because DMARC reports every sending source using your domain, including ones you may have forgotten about (marketing tools, invoicing systems, old mail servers). Jumping straight to reject can silently block that legitimate mail. Monitoring first lets you see the full picture in the aggregate reports before anything gets blocked.
›What does the pct= percentage actually control?
It tells receiving mail servers to only apply your quarantine or reject policy to that percentage of messages that fail DMARC, picked at random, the rest fall back to the next weaker policy. It is a gradual rollout dial: 25% today, 50% next week, 100% once you are confident nothing legitimate is being caught.
›Relaxed vs strict alignment, which should I pick?
Relaxed (the default for both adkim and aspf) allows the From address domain and the SPF/DKIM-authenticated domain to be organizational matches, like mail.example.com authenticating for example.com. Strict requires an exact match. Most domains should leave both on relaxed unless they have a specific reason to tighten it, since strict mode breaks many legitimate subdomain sending setups.
›Where do I actually publish this record?
Add it as a TXT record at the host shown above (_dmarc, or _dmarc.yourdomain.com depending on your DNS provider's interface) in the DNS zone for your domain. It can take anywhere from a few minutes to 48 hours to propagate, depending on your provider and DNS TTL settings.
Related Tools
Text
Number Base Converter
Convert a number between binary, octal, decimal, hexadecimal, BCD, Gray Code, and any custom base from 2 to 36, all at once from a single input.
FreeText
Bcrypt Hash Generator Checker
Generate and verify bcrypt password hashes entirely in your browser using WebAssembly, with an adjustable cost factor and salt.
FreeText
Bionic Reading Converter
Convert any text into bionic reading format by bolding the first portion of each word to help you read faster and focus better.
FreeText
Blake2b Hash Generator
Compute the BLAKE2b hash of text or a file in your browser, with adjustable output length and optional keyed hashing (MAC).
FreeText
Caesar Cipher Tool
Encrypt or decrypt text with a classic Caesar cipher, with an A-Z mapping table, brute-force list, letter-frequency chart, and ROT13 shortcut.
FreeText
ASCII Art Generator
Turn typed text or an uploaded image into ASCII art. Choose a font style or character ramp, preserve color, and export as plain text or PNG.
FreeText
Secrets/Config Redactor
Paste a .env or config file and automatically mask API keys, passwords, and tokens next to sensitive key names or known secret formats (AWS, GitHub, Stripe, JWT, PEM). Safe to then paste into a chat AI or bug report.
FreeText
Cron Expression Generator
Build and parse cron expressions with a live field editor, plain-English description, and the next 5 actual run times. Supports presets, @ shortcuts, and the optional 6-field seconds variant.
Comments (0)
Found this tool useful? Leave a comment, share a tip, or tell us how we can make it better.
No comments yet. Be the first to share your thoughts!