Free tool

DMARC Record Analyzer

Parse your DMARC policy, alignment modes, and reporting addresses. Flags weak configurations and missing pieces.

What this tells you

Whether you have a DMARC record at all, what policy is published, where reports go, and whether the configuration looks production-grade or like a monitor-only setup someone forgot to ramp up.

The fail modes

The two most common DMARC misconfigurations: p=none with no rua (you have a record but it does nothing and gives you no visibility), and p=reject with pct < 100 (you've ramped enforcement but somehow forgot to set pct=100, leaving 90% of failing mail un-rejected).

What we don't check (yet)

Actually parsing your aggregate reports. That requires an XML inbox and is its own product (see Postmark DMARC Digest, dmarcian, EasyDMARC). What we do: monitor the record itself for changes and configuration drift.

FAQ

What does the DMARC analyzer check?
It resolves the TXT record at _dmarc.<your-domain>, parses every tag (p, sp, rua, ruf, pct, adkim, aspf, fo), and flags configurations that are likely incorrect, for example p=none without rua, or pct below 100 in what looks like a production setup.
My DMARC policy is "none". Is that bad?
p=none is fine for the first 2-4 weeks of deployment while you collect aggregate reports to discover all your legitimate senders. Past that, it provides no protection. The goal is to ramp to p=quarantine, then p=reject.
What does "no rua tag" mean?
rua is where aggregate reports get sent. Without it, you get no visibility into who is sending mail as your domain, which makes diagnosis impossible. Always include rua= pointing to a DMARC aggregator like Postmark, dmarcian, or EasyDMARC.
What's the difference between strict and relaxed alignment?
Relaxed (r) treats subdomains as aligned, mail signed by mail.example.com aligns with From: example.com. Strict (s) requires exact match. Use relaxed for the first year unless you have specific reasons otherwise.
Related