Validate a domain's DMARC record and see whether your policy actually protects you.
Enter a domain to check its DMARC configuration.
DMARC builds on SPF and DKIM to tell receiving servers what to do when a message fails authentication, and where to send reports. It is the record that actually stops attackers spoofing your domain.
A DMARC record set to p=none only monitors; it does not block spoofing. This checker confirms your policy exists, reads its enforcement level, and flags whether reporting is configured.
DMARC is published as a TXT record at the _dmarc subdomain, for example _dmarc.example.com. This checker queries that name for you automatically when you enter your domain.
p=none only monitors and reports without affecting delivery. p=quarantine sends failing mail to spam. p=reject blocks it outright. Start at none to gather reports, then tighten to quarantine and finally reject.
Yes. DMARC relies on SPF and DKIM results plus alignment. Set up and verify both first, otherwise moving DMARC to enforcement could block your own legitimate mail.
Every one runs a real check, live, with nothing to install.
A one-off check is useful, but PulseStack repeats it every minute and alerts you the moment something changes. Start free with 5 monitors, no card required.