DMARC Record Generator
Free DMARC record generator. Choose your policy, reporting addresses and alignment, and get a valid DMARC TXT record to publish - with guidance at each step. No login.
RFC 9989New tag in the 2026 DMARC update (DMARCbis)
RFC 9989New tag in the 2026 DMARC update (DMARCbis)
About the DMARC Record Generator
Use this free DMARC record generator to build a valid DMARC TXT record for your domain. Choose your enforcement policy, add the reporting addresses that let you see who is sending as your domain, set alignment, and the tool assembles the exact record to publish - with plain-English guidance on what each choice does.
The safest path is to start in monitoring mode (p=none) with a reporting address, watch the reports until your legitimate mail passes consistently, then tighten to quarantine and finally reject. This generator flags risky combinations so you do not accidentally block your own mail.
The generator is current with the 2026 DMARC spec (DMARCbis, RFC 9989): it supports the new np= tag for non-existent subdomains and the t= testing flag, and no longer emits the retired pct= tag - RFC 9989 receivers ignore pct entirely, so a percentage rollout is dead weight in a new record. Ramp up over time instead: none, then quarantine, then reject.
Frequently asked questions
How do I create a DMARC record?
Choose a policy (start with p=none), add a rua reporting address, and publish the generated record as a TXT record at _dmarc.yourdomain.com. This generator assembles the exact record for you.
What should my first DMARC record be?
Begin with p=none plus a rua address so you collect reports without affecting delivery. After a few weeks of clean reports, move to p=quarantine, then p=reject.
What is a rua address in DMARC?
rua is where aggregate DMARC reports are sent - a mailbox you monitor to see who is sending as your domain, including spoofers. Always include one so you are not moving to enforcement blind.
What are the np= and t= tags (DMARCbis)?
Both were added in the 2026 DMARC update (RFC 9989). np= sets the policy for non-existent subdomains - ones with no DNS records - and np=reject is the cheapest anti-spoofing win, since no legitimate mail can come from a subdomain that does not exist. t=y marks the whole record as testing: receivers on RFC 9989 apply your policy one level gentler (reject is handled as quarantine, quarantine as none), while older RFC 7489 receivers ignore it. Remove t=y when you are ready to enforce fully.
Why is there no pct option any more?
The pct= percentage tag was removed in RFC 9989 - modern receivers ignore it, so a new record carrying pct is dead weight and older receivers would only partially enforce it. To roll out gradually, ramp over time (none, then quarantine, then reject) or use t=y during the quarantine and reject steps.
Did this check reveal a problem?
Postbox Consultancy Services fixes email deliverability for a living - 500+ clients over 10+ years. Authentication, blacklist recovery, cold email infrastructure and full audits.