DMARC record generator: build your _dmarc record in one minute
Pick a policy, enter a report address and copy the record. A DMARC record is a TXT record at _dmarc.yourdomain.com that tells receivers what to do with email that fails both SPF and DKIM, and where to send reports. Start with p=none, read the reports, then tighten to quarantine and reject.
The generator builds the value live as you choose. What each tag means is shown next to the field; the order in which to tighten the policy is at the bottom.
Putting the record live — and tightening it safely
DMARC only works once SPF and DKIM are already in place. Publish the record, wait for reports and raise the policy in steps.
Publish the TXT record
In the DNS management of your registrar or hosting panel, create a TXT record named _dmarc (or _dmarc.yourdomain.com, depending on the panel) with the value above.
Read reports for two weeks
The reports show which sources send on behalf of your domain and whether they pass SPF/DKIM. Anything legitimate that fails must be fixed first.
Raise to quarantine and reject
Once your own mail passes everywhere, set p=quarantine (optionally with pct), and after a quiet period p=reject. Your domain is then protected against abuse.