Policy Builder

DMARC Record Generator

Generate a starter DMARC record with a policy, reporting address, alignment defaults, rollout percentage, and safe publishing guidance.

Step 1

Start Here

Enter the record settings and run DMARC Record Generator.

Runs in your browser. Nothing is added to Mailrith.

Step 2

Review the DMARC Generator Result

Review the status, warnings, and recommended actions shown in the result panel.

Ready When You Are

Run DMARC Record Generator to see the DMARC Generator result and next actions.

About DMARC Record Generator

A DMARC generator helps create the DNS TXT record that tells inboxes how to handle mail that fails authentication checks for your domain. It is useful when you need a monitoring record, a reporting address, or a gradual path toward stricter protection. Read DMARC before publishing a policy that affects live mail.

For most domains, the safe path is to start with monitoring, review reports, fix legitimate senders, and then move toward quarantine or reject when authentication is ready. The DMARC record generator explains the policy, percentage, reporting, and alignment choices in simple terms. Before enforcement, use DMARC Alignment so SPF or DKIM can pass for the visible From domain.

What DMARC Record Generator Checks

  • Domain and reporting address format
  • Policy choice: none, quarantine, or reject
  • Rollout percentage
  • Relaxed SPF and DKIM alignment defaults
  • Suggested TXT value
  • Safe rollout guidance

Questions

Should I start with p=reject?

Usually no. Start with p=none if you are still discovering senders. Move to quarantine and reject only after legitimate mail passes aligned SPF or DKIM.

Do I need a reporting email?

A reporting address is strongly recommended. Without reports, it is harder to see which systems send as your domain and what might break.