Email Security
DMARC Record Validator & Policy Inspector
Inspect and validate Domain-based Message Authentication, Reporting, and Conformance (DMARC) records per RFC 7489. DMARC builds on SPF and DKIM to give domain owners control over what happens when an email fails authentication. With the right DMARC policy (p=reject), you can stop domain spoofing and phishing attacks that impersonate your brand. Audit policy enforcement (none, quarantine, reject), verify alignment tags, and test RUA mailto reporting endpoints.
Key Capabilities & Features
dnsfyi combines high-speed global Anycast DNS queries with comprehensive security auditing into a unified diagnostic suite.
- • DMARC policy enforcement inspection (p=reject, p=quarantine, p=none)
- • RUA and RUF aggregate reporting email destination validation
- • DKIM and SPF identifier alignment mode checks (aspf, adkim — strict vs relaxed)
- • pct= percentage policy application check
- • Subdomain policy (sp=) inspection
- • Step-by-step policy upgrade guidance from p=none to p=reject
How to Use This Tool
To audit any domain or IP address, enter the hostname into the search box to run an instant parallel multi-resolver inspection.
- Enter your domain name to automatically look up the DMARC TXT record at _dmarc.yourdomain.com.
- Review the current policy: p=none (monitor only), p=quarantine (spam folder), or p=reject (block).
- Check the RUA (aggregate report) email address — this is where daily DMARC reports from receiving servers are sent.
- Verify alignment settings: aspf=r (relaxed) allows subdomain alignment; aspf=s (strict) requires exact match.
- Follow the upgrade path: start with p=none, analyze RUA reports, fix SPF/DKIM issues, then advance to p=quarantine and p=reject.
Common Use Cases
dnsfyi is primarily used to troubleshoot email deliverability failures, verify global DNS propagation, and audit SSL certificate health.
- → Verifying DMARC is correctly published before enabling strict email enforcement.
- → Diagnosing why aggregate DMARC reports show authentication failures from legitimate senders.
- → Checking subdomain policy (sp=) to ensure subdomains are protected from spoofing.
- → Confirming RUA reporting is configured correctly to receive DMARC XML feedback reports.
- → Auditing pct= value to gradually roll out policy changes with controlled percentage enforcement.
Frequently Asked Questions
Find direct answers about dnsfyi's multi-resolver query engine, privacy policy, domain security checks, and free REST API.
- What is the safest way to deploy DMARC?
- Start with p=none to monitor aggregate RUA reports without impacting mail flow. Identify all legitimate email senders, fix SPF/DKIM alignment issues, then gradually transition to p=quarantine (spam folder) and finally p=reject (block). This migration typically takes 4–8 weeks.
- What is a DMARC RUA report?
- RUA (Reporting URI for Aggregate) reports are XML files sent daily by receiving mail servers (Gmail, Outlook, etc.) to your specified email address. They show which IPs are sending mail on your domain's behalf and whether SPF/DKIM authentication passed or failed. Use a DMARC report analyzer to parse these files.
- What is DMARC alignment?
- DMARC alignment requires that the domain in the SPF envelope sender or DKIM d= tag matches the RFC5322 From: header domain. Relaxed alignment (aspf=r / adkim=r) allows subdomain matches. Strict alignment (aspf=s / adkim=s) requires an exact domain match.
- Can I have DMARC without DKIM?
- Yes, DMARC can pass with SPF alignment alone. However, DKIM-signed messages are more reliable because SPF breaks when emails are forwarded (the forwarding server's IP may not be in your SPF record). It is strongly recommended to configure both SPF and DKIM.
- What does pct= mean in a DMARC record?
- pct= specifies the percentage of messages subject to DMARC policy filtering. For example, pct=10 means only 10% of failing messages get the quarantine or reject treatment. This lets you test the policy impact gradually before going to 100% enforcement.
- Why is my DMARC policy not being enforced?
- Common reasons: (1) Your DMARC record has p=none which is monitoring-only. (2) The DMARC record is published at the wrong location — it must be at _dmarc.yourdomain.com. (3) SPF and DKIM are not correctly aligned with the From: domain. Check alignment tags aspf= and adkim=.