How to Set Up DMARC: Step-by-Step Guide for 2026

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a DNS record that tells receiving servers what to do when an email fails SPF or DKIM authentication. Without DMARC, you have no visibility into who's sending as your domain, and you can't enforce a policy that protects your domain from spoofing.

Setting up DMARC is a 5-step process. Here's how to do it.

Check Your DMARC Record in 30 Seconds

Run a free DMARC record check on your domain. No signup, no credit card. Get the exact record to fix.

Run My Free Test

Step 1: Check Your Existing DMARC Record

Before you set up DMARC, check if you already have a DMARC record. You can do this with dig or nslookup:

dig TXT _dmarc.yourdomain.com

If you already have a DMARC record, review it to make sure it's configured correctly. If you don't have a DMARC record, you'll need to create one.

Step 2: Choose Your DMARC Policy

DMARC has three policies:

Start with p=none and move to p=quarantine or p=reject as you gain confidence in your DMARC setup.

Step 3: Add the DMARC Record to Your DNS

Create a new TXT record in your DNS with the name _dmarc and the value v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com. Replace yourdomain.com with your actual domain.

The rua directive tells receiving servers where to send their DMARC reports. This is how you'll know if anyone is sending email as your domain.

Step 4: Monitor Your DMARC Reports

After you've added your DMARC record, start monitoring your DMARC reports. You can use a free tool like InboxProof to aggregate and parse your DMARC reports, or you can use a paid tool like dmarcian or Red Sift.

Review your DMARC reports regularly to make sure no one is sending email as your domain. If you see any unauthorized senders, you'll need to update your SPF record to include their mail servers, or you'll need to move your DMARC policy to p=quarantine or p=reject.

Step 5: Move to a Stricter Policy

Once you've confirmed that all your legitimate email is passing SPF or DKIM, move your DMARC policy to p=quarantine or p=reject. This will start enforcing your DMARC policy and protecting your domain from spoofing.

Move to p=quarantine first, and wait a few weeks to make sure no legitimate email is being affected. Then move to p=reject for full protection.

Find Out If Your DMARC Record Is Set Up

Run a free DMARC record check on your domain in about 30 seconds. Get the exact record to fix. No signup required.

Run My Free Test