Alignment needs a real message
DMARC passes when SPF or DKIM passes and its authenticated domain aligns with the visible From domain. DNS policy alone cannot prove that.
Current policy evidence · read-only DNS
Find the policy that applies to a From domain, see whether it is direct or inherited, and understand alignment, subdomain handling and public report destinations using the current DMARC standard.
Check a DMARC policyInspect a From domain
Enter the domain shown after @ in the visible From address. The checker performs a bounded RFC 9989 policy walk and reads public TXT records.
Public DNS check. We read the DMARC policy published for this domain and explain the settings we find. Nothing is changed.
Read the result correctly
DMARC passes when SPF or DKIM passes and its authenticated domain aligns with the visible From domain. DNS policy alone cannot prove that.
None, quarantine and reject communicate requested handling for DMARC failures. Receivers can consider local policy, indirect flows and other evidence.
Message-specific reports can expose headers or content containing personal or confidential information. Many receivers decline to send them.
The policy, tree-walk and tag explanations follow RFC 9989; reporting follows RFCs 9990 and 9991.
Read RFC 9989DMARC questions
No. It checks the discoverable DNS policy, not a message. Use a real message's Authentication-Results header and aggregate reports to assess SPF or DKIM pass and alignment.
No. It expresses the domain owner's requested handling. Receiving systems can apply local policy and consider other evidence, including the risks of indirect mail flows.
RFC 9989 marks pct as historic after inconsistent real-world sampling. This checker does not treat a legacy percentage as reliable current policy coverage; the current standard defines t=y for test mode.
No. It can parse the public URI and check a clearly external destination's authorization record. It cannot confirm that a mailbox exists, accepts reports or is actively monitored.
Not from this result alone. First identify every legitimate sender, validate aligned SPF and DKIM on representative mail, review aggregate reports and keep a tested rollback plan.