Website diagnostics
DMARC Check & Lookup
Run a free DMARC check and lookup online with Web Health. Verify your DMARC record, policy enforcement, reporting addresses, and protection against email spoofing.
Understanding DMARC Email Security
DMARC builds upon SPF and DKIM authentication protocols to give domain owners full control over email deliverability and spoofing defense. Implementing DMARC prevents cybercriminals from impersonating your brand in executive spear-phishing or customer scam campaigns.
Key DMARC Record Tags
- v=DMARC1: Required protocol version header tag.
- p=none / quarantine / reject: Core policy enforcement directive.
- rua=mailto:...: Destination URI for daily aggregate feedback reports.
- ruf=mailto:...: Destination URI for real-time forensic failure alerts.
- pct=100: Percentage of messages subject to policy filtering.
- aspf / adkim: SPF and DKIM domain alignment mode (r=relaxed, s=strict).
DMARC Implementation Roadmap
- Step 1: Publish 'v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com' TXT record.
- Step 2: Analyze weekly aggregate reports to map legitimate email platforms.
- Step 3: Configure DKIM signing and SPF inclusion for all valid senders.
- Step 4: Escalate policy from p=none to p=quarantine, then p=reject for full protection.
Frequently Asked Questions
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email security protocol published in DNS at '_dmarc.yourdomain.com'. It tells receiving mail servers how to handle emails claiming to be from your domain that fail SPF or DKIM alignment checks.
