DMARC checker — validate your domain's DMARC policy
Since 2024 no DMARC means rejections at Google and Yahoo; since May 2025 a hard 5.7.515 reject at Microsoft. See where you stand.
What DMARC is
DMARC (RFC 7489) is a TXT record at _dmarc.domain that ties SPF and DKIM to the visible From header: a message passes when SPF or DKIM passes and aligns with the From domain. The p= policy tells receivers what to do with the rest: none (only report), quarantine (spam folder), reject. rua reports deliver daily aggregates of who sends on your behalf.
2024–2026 requirements
Google and Yahoo (February 2024): senders above 5,000 messages/day need SPF and DKIM, DMARC (at least p=none) with alignment, one-click unsubscribe and a spam rate below 0.3%. Since November 2025 Gmail is “ramping up enforcement”. Microsoft (May 2025): ≥ 5,000/day to outlook.com/hotmail — SPF, DKIM, DMARC required; missing = 550 5.7.515 Access denied. This covers practically every shop, SaaS and newsletter.
Rolling out DMARC safely
Step 1: v=DMARC1; p=none; rua=mailto:dmarc@yourcompany.com — nothing changes, collect reports for 2–4 weeks. Step 2: fix the sources that fail (usually CRM, invoicing, printers). Step 3: p=quarantine; pct=25, then 100. Step 4: p=reject. Add sp= for subdomains and adkim=s once every source signs with the exact domain.
FAQ
Is p=none enough?
To meet the Google/Microsoft minimum — yes. To protect your brand from phishing — no; aim for p=reject.
Where do I get a rua address?
Any mailbox in your domain; reports are XML. Easier: a report-parsing service (SpamTest Pro provides its own rua address and charts).