Evidence-led rollout · private browser draft
DMARC record builder for safer email policy.
Create a reviewable RFC 9989 DMARC TXT draft and a staged path from monitoring to enforcement. Stronger policies stay behind evidence and rollback checks.
Plan a DMARC stageA defensible rollout
Policy follows evidence, not ambition.
A DMARC record does not create SPF or DKIM alignment. It tells receivers how the domain owner would prefer failed messages to be handled and where supported reports may be sent.
- 01Inventory
List every service that sends with the visible From domain and identify its aligned SPF or DKIM path.
- 02Observe
Start with aggregate reporting and review representative traffic, including low-frequency and indirect flows.
- 03Test one level
Use
t=ywhen the next requested policy needs a controlled test under the current standard. - 04Approve and verify
Preserve the old record and TTL, schedule rollback, then verify public DNS and legitimate mail after any change.
Current primary standards
Built around DMARC's current specification.
The builder uses the May 2026 DMARC standard and its current reporting specifications. Provider-specific implementation guidance still takes priority for your service.
DMARC builder questions
What this draft can and cannot decide.
Should I start with p=reject?
No. Start with sender inventory and monitoring, review representative reports, test the next level and keep a rollback path. Reject can disrupt legitimate mail when a sender or indirect flow was missed.
Why does the builder use t=y instead of pct?
RFC 9989 marks the older pct sampling tag as historic. Its current test-mode tag lowers the requested action by one level: reject to quarantine, or quarantine to none.
Do I need both SPF and DKIM to pass DMARC?
No. A message can pass DMARC when at least one authenticated path passes and aligns with the visible From domain. Having both working improves resilience across different mail flows.
Can I send reports to another domain?
Yes, but the destination can require a public authorization record before receivers send reports there. Confirm the reporting provider's exact setup and inspect the published result.
Does p=reject guarantee rejection?
No. It publishes the domain owner's requested handling policy. Receivers retain local discretion, and a generated record cannot guarantee delivery, rejection or inbox placement.