← Record Studio

DMARC

DMARC (RFC 9989, “DMARCbis”) tells receivers what to do with mail that fails SPF and DKIM alignment, and where to send reports. The policy is published as a TXT record at _dmarc.<domain>.

Recommended rollout (RFC 9989 §7.4): start with p=none plus rua reporting and monitor for about a month, move to p=quarantine for a similar period, then finish with p=reject. Only p=reject provides full spoofing protection – the security check rates p=none as a failure for exactly that reason.
DMARCbis removed the pct, ri and rf tags and the !size suffix; this generator never emits them. Percentage sampling is replaced by the t=y test flag.
Policy (p=)

Email addresses, comma-separated; converted to mailto: URIs with , and ! percent-encoded.

Per-message failure reports; few receivers send them.

Runs entirely in your browser. Record Studio · Verify the result with the domain security check