SecurityEDGE RESOLUTION

DMARC Lookup

Check a domain's DMARC policy to ensure proper email authentication.

Technical Specification & Reference

What this tool does

Reads the `_dmarc` TXT record for a domain and explains the policy in plain terms — none, quarantine, or reject — along with the reporting addresses configured to receive authentication failure reports.

Why DMARC matters

DMARC is what actually enforces the results of SPF and DKIM. Without a DMARC policy, a receiving mail server can see that SPF or DKIM failed but has no domain-published instruction on what to do about it — many will still deliver the mail. A DMARC record with a reject or quarantine policy tells receiving servers to actually act on authentication failures, closing the gap that lets spoofed mail through even when SPF and DKIM exist.

Understanding the policy levels

A `p=none` policy only requests reporting with no enforcement — a reasonable starting point while monitoring reports, but it doesn't stop spoofed mail from being delivered. `p=quarantine` sends failing mail to spam. `p=reject` blocks it outright and is the end goal for a domain that's confirmed its legitimate mail sources are all properly authenticated.

Frequently Asked Questions

What's the difference between p=none, quarantine, and reject?

none only requests reporting with no enforcement; quarantine sends failing mail to spam; reject blocks it outright. Most domains start at none while monitoring reports, then move to stricter enforcement once confident.