Free tool

Free DMARC checker

Check your DMARC record and policy against the updated DMARCbis standard: whether spoofed email is blocked, whether you're getting reports, and what to tighten next. Plus your SPF record. No signup.

We look up your public DNS records. Nothing is sent or stored.

What the result means

What DMARC does

Without DMARC, anyone can send an email that claims to come from your domain, and receiving servers have no instruction from you on what to do about it. That's how invoice-fraud and fake-supplier emails work. DMARC is a record at _dmarc.yourdomain that tells receivers to check SPF and DKIM against the From address people actually see, and what to do when those checks fail: nothing (p=none), send to spam (p=quarantine) or refuse the message (p=reject). It also asks receivers to send you reports, so you can see every service sending as your domain.

Reading your result

No record is red: your domain can be spoofed freely, and Gmail and Yahoo expect bulk senders to publish one. p=none is amber: a sensible starting point, but it only monitors. p=quarantine or p=reject is green. We also flag a missing reporting address (rua=), a weaker policy for subdomains (sp=), and records that are inherited from a parent domain.

DMARCbis: what changed

DMARCbis is the updated DMARC standard that replaces the original specification. Three changes affect your record. The pct= tag is gone, so receivers following the new standard apply your policy to all failing mail rather than a percentage; if your record still uses pct= to roll out gradually, that no longer works reliably. A new t=y flag marks a testing phase instead. And np= lets you set a policy for subdomains that don't exist, which closes a common spoofing gap. This checker reports all three. SPF is checked alongside, and the SPF checker covers it in full.

This is one check. Your site needs dozens.

The full AuditCrow audit runs this alongside speed, SEO, accessibility, trust and AI readiness, then tells you what to fix first, in plain English.

FAQ

Common questions

Straight answers about what this check does, and doesn't do.

What is DMARC?

DMARC is a TXT record at _dmarc.yourdomain that tells receiving mail servers what to do with email that fails SPF and DKIM checks for your domain (nothing, send to spam, or reject), and where to send reports about it.

What is DMARCbis?

DMARCbis is the updated DMARC standard, replacing the original 2015 specification. The changes that matter most for your record: pct= is dropped (receivers apply your policy to all failing mail), t=y is the new way to signal a testing phase, and np= sets a policy for subdomains that don't exist.

Is p=none enough?

It's the right place to start, and Gmail and Yahoo expect bulk senders to have at least that. But p=none only monitors: spoofed mail is still delivered. Use the reports to confirm your real senders pass, then move to p=quarantine and p=reject.

My subdomain has no DMARC record. Is it unprotected?

Not necessarily. Receivers fall back to the organisational domain's record (using its sp= policy if set). This checker does the same and tells you when a policy is inherited.

Join the waitlist

Be first when scans reopen

Scans are paused for a moment. Join the waitlist and we'll tell you when they're back.

We'll email you when free scans are back