DMARC checker
Look up and understand any DMARC record.
A DMARC checker reads the public TXT record for a hostname, shows the raw value and parser findings, and explains which policy was observed. It is a read-only DNS review, not a message test or a promise of inbox placement.
What the lookup reads
Useful DNS evidence, kept separate from message-level results.
The tool keeps the record and its interpretation visible so a sending team can inspect the same evidence together. It does not silently rewrite a record or turn a DNS observation into a sender-readiness badge.
Raw TXT value
See the value returned at _dmarc.<domain>, including multiple values when returned.
Parsed tags
Review policy, alignment, reporting, and current or historic tags in plain language.
Policy discovery
See whether the result is direct or inherited from a parent DNS name.
Related SPF audit
Review the SPF record status, lookup count, and void lookup count returned with DMARC.
Read the result
Status is not the same as readiness.
A record can be present while a message still fails alignment. Use the status below to decide what to investigate next, not to certify a campaign.
| Status | Meaning |
|---|---|
| ok | A record was found and parsed. Review the observed policy and findings in context. |
| not_found | No usable record was found in the queried DNS names. |
| invalid | A candidate record was found, but validation findings mean it needs review. |
| dns_error | The lookup did not complete, so no policy conclusion is available. |
Current standard context
RFC 9989 context without removing the need for review.
RFC 9989 recognizes tags including np, t, and psd. It treats pct, rf, and ri as historic. Older receivers may still read those fields, so the checker labels them as observed historic values and leaves policy decisions with the operator.
The result can show an inherited policy when the author domain has no usable record. Review the record domain and policy source before drawing conclusions about a subdomain.
Provider guidance
Use current guidance for the sender and the message.
Google's sender guidance and the DMARC RFC describe separate authentication and alignment requirements. A DNS checker can show that a record exists, but only a real message and aggregate reporting can show how a sender aligns in practice.
For a broader public-signal review, compare this result with the domain reputation checker. For a product-specific DMARC workspace, visit dmarc.folderly.com.
Limits to keep in view
A DMARC lookup is one part of an authentication review.
- It does not send or inspect an email message.
- It does not prove SPF or DKIM alignment for a specific message.
- It does not inspect aggregate report contents or complaint history.
- It does not change DNS or generate a record to publish.
- It does not certify compliance for Gmail, Yahoo, Outlook.com, or another provider.
- It does not guarantee inbox placement.
Frequently asked questions
DMARC checker questions
How do I check a DMARC record?
Enter a hostname such as example.com. The checker queries the public DNS names used for DMARC, then shows the raw TXT value, parsed tags, status, inheritance, findings, report-destination observations, and an SPF lookup audit. It does not change DNS.
What does p=none tell me?
p=none is a monitoring policy for mail that fails DMARC. It is one DNS observation, not a provider compliance or message-alignment result. Review aggregate reports and current mailbox-provider guidance before changing policy.
What is the difference between p=quarantine and p=reject?
Both policies apply to mail that fails DMARC. quarantine asks a receiver to treat that mail as suspicious, while reject asks the receiver to refuse it. The checker displays the policy it observed and does not recommend an automatic change.
What changed with RFC 9989?
RFC 9989 is the current DMARC protocol update. It recognizes tags such as np, t, and psd, and treats pct, rf, and ri as historic. Receivers that still implement RFC 7489 may read the historic tags, so this checker labels observed values without turning them into an automatic enforcement recommendation.
Can this checker prove that a message will reach the inbox?
No. A DNS lookup cannot prove per-message SPF or DKIM alignment, mailbox-provider reputation, complaint history, or inbox placement. Use the result as an authentication review and confirm message-level behavior with your sending and reporting systems.
Sources
Primary references
Standards and provider guidance can change. Check the source before making a production DNS decision.
Last reviewed: September 28, 2026