DMARC checker
Look up a domain's DMARC record, see whether it actually stops spoofing, and get a copy-paste fix. Free, no signup.
What this DMARC check looks at
We read the TXT record at _dmarc.yourdomain.com using public DNS-over-HTTPS. If you enter a subdomain without its own record, we check the organizational domain too, and use its sp= policy if one is set.
- Pass:
p=rejectorp=quarantinecovering 100% of mail. - Warning:
p=none(monitoring only), orpctbelow 100. - Fail: no record, more than one record, or an invalid policy.
The same lookup also runs the rest of the StackGrade checks (SPF, DKIM, security headers and domain expiry), so you see the full picture below.
Frequently asked questions
What is DMARC?
DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS TXT record at _dmarc.yourdomain.com. It tells receiving mail servers what to do with messages that claim to be from your domain but fail SPF and DKIM alignment: deliver them (p=none), send them to spam (p=quarantine) or block them (p=reject). It also tells them where to send reports.
Do I need DMARC for Gmail and Yahoo?
Yes, if you send in bulk. Since 2024, Google and Yahoo require bulk senders (roughly 5,000+ messages a day to their users) to publish a DMARC record (p=none is the minimum), plus SPF and DKIM. Smaller senders must have SPF or DKIM, and DMARC is strongly recommended.
Is p=none good enough?
p=none is a safe first step because it only collects reports. It does not stop anyone from spoofing your domain. Once the reports show that all your real email passes SPF or DKIM, move to p=quarantine and then p=reject.
What should my first DMARC record look like?
A common starting point is: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com. Use a mailbox you actually read (or a DMARC report service), because reports arrive daily as XML attachments.
Why does the checker say "more than one DMARC record"?
Receivers ignore DMARC entirely when there are two or more v=DMARC1 TXT records at _dmarc. Merge them into one.
How long until a DMARC change shows up?
DNS changes usually appear within minutes. Records can take up to their TTL (often 1 hour, sometimes up to 24 hours) to update everywhere. Use Re-check to run the lookup again.
How StackGrade works
Email authentication · 50 pts
SPF (including the 10-lookup limit), DMARC policy, DKIM keys at common selectors, and MX. These decide whether Gmail and Yahoo trust your mail, and whether scammers can spoof you.
Website security · 35 pts
HTTPS redirect, HSTS, Content-Security-Policy, clickjacking protection, X-Content-Type-Options, Referrer-Policy and cookie flags, using Mozilla's public HTTP Observatory scan.
Domain health · 15 pts
Expiry date and registrar transfer lock from the official registry (RDAP). Domain age, email provider, tech stack and hiring signals are shown but not scored.
Honest by design
If a check can't run (the registry has no RDAP, the site blocks scanners, a lookup times out), we show Not checked with the reason and leave it out of the score. We never guess. The full rubric is public.
Privacy
The checks run in your browser, which asks public services directly: Google Public DNS / Cloudflare DNS, the domain's registry RDAP server, Mozilla HTTP Observatory (its scan history is public) and public job boards (Greenhouse, Lever, Ashby, Workable). For the tech-stack scan, the StackGrade API fetches the site's public homepage; the result is kept briefly in memory, never stored. Graded domains are not logged. Details in the privacy policy. Page views are counted with GoatCounter (open source, no cookies, no personal data); only the page path is sent, never the domain you check.