How to Check a DMARC Record and Fix Common Problems
A DMARC policy is normally published as a TXT record at _dmarc.yourdomain.com. Checking the exact published value is the first step before changing the policy.
Where DMARC lives
DMARC is not normally placed on the root hostname. For example, the DMARC record for example.com is queried at _dmarc.example.com.
Understand the policy
The p tag states the requested policy. p=none is primarily monitoring, p=quarantine asks receivers to treat failing messages with greater suspicion, and p=reject requests rejection of messages that fail the DMARC evaluation.
Common DMARC problems
Common issues include publishing the record at the wrong hostname, malformed tags, more than one DMARC record, moving to enforcement before legitimate sending services are authenticated, and assuming DMARC replaces SPF or DKIM.
Before tightening the policy
Inventory legitimate senders and verify their SPF/DKIM alignment. If your organisation depends on several mail platforms or third-party senders, review their authentication setup before making a restrictive policy change.
Check your domain
Use ZoneCheckr to inspect the live configuration before making changes.
Check DMARC & Email SecurityStill stuck? Get technical help with your domain →