Free tool

DMARC record generator.

Builds the record, and tells you honestly which policy you should actually be publishing today.

Starts at monitor only, on purpose. See below for why.

Why this one starts at p=none

Most generators will hand you p=reject on the first screen. That is how businesses block their own invoices.

Reject acts on mail. The senders that break are the ones you had forgotten about: the invoicing tool, the CRM, the form on the website that has been sending from a server nobody documented. You find out when somebody tells you their mail bounced, which is usually a customer.

So the order is not optional. Publish p=none, read the aggregate reports for about a month, authorise every legitimate sender, and only then tighten. That sequence is the entire subject.

The three policies

  • none — reports what fails, delivers everything. Where you start, and where most domains correctly stay for months.
  • quarantine — failing mail goes to spam. The first policy that actually does something, and the first that can hurt.
  • reject — failing mail is refused outright. Correct destination, wrong starting point.

The full guide covers the sequence properly.

Check everything at once.

One check covering registration, certificates, mail, subdomains and hosting.