On this page
  1. What the message means
  2. Does it affect your email?
  3. How to publish a DMARC record
  4. Before you start
  5. 1. Choose where reports go
  6. 2. Write the record
  7. 3. Add it at your DNS host
  8. 4. Check it
  9. Checked a subdomain?
  10. Still not found after publishing?
  11. Next: from monitoring to enforcement
  12. Sources

"No DMARC record found" means the checker did not find a DMARC record for the domain you entered (MXToolbox (opens in a new tab)). If you checked a subdomain, first see whether its parent domain's policy covers it (RFC 9989 section 4.10.1 (opens in a new tab)). If no policy applies, publish one DNS (Domain Name System) TXT (text) record (opens in a new tab) at _dmarc.example.com, with your domain in place of example.com, start at p=none with a reporting address, and check again.

What the message means

RFC 9989 (opens in a new tab), which obsoletes RFC 7489, defines DMARC (Domain-based Message Authentication, Reporting, and Conformance). A domain's DMARC record is a TXT record in DNS at the name made by putting the label _dmarc in front of the domain (section 4.1 (opens in a new tab)). MXToolbox (opens in a new tab) shows this message when your domain does not have a published DMARC record.

Receivers look in the same place. They take the domain from the message's From address (section 5.3 (opens in a new tab)) and query _dmarc in front of it; if no valid record is there, they look for the record of its parent domain (section 4.10.1 (opens in a new tab)). If they find no record at all, DMARC does not apply to the message.

DemiSignal's check flags a missing DMARC record too. It reports a fail when the record is missing or broken, and an error when the DNS lookup did not complete, in which case run the check again.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.

Does it affect your email?

DMARC builds on two other checks. Sender Policy Framework (SPF) (opens in a new tab) lets the owner of the MAIL FROM (envelope sender) domain publish which hosts may use it, and receivers test the sending server against that list. DomainKeys Identified Mail (DKIM) (opens in a new tab) signs some or all of a message so receivers can confirm the signed content has not changed. To pass DMARC, a message needs an SPF or DKIM pass for a domain aligned with the domain in its From address (RFC 9989 section 1 (opens in a new tab)). For messages that fail, the DMARC policy tells receivers what to do: reject, quarantine or no instruction (Microsoft (opens in a new tab)).

Without an applicable DMARC record, receivers have no DMARC policy from you to apply, and the final handling of your mail stays with each receiver's own policies (RFC 9989 section 5.4 (opens in a new tab)). In Microsoft 365, the dmarc result in a message's Authentication-Results header can then be bestguesspass: no DMARC record exists for the sender's domain, and Microsoft 365 inferred a pass using heuristics (Microsoft (opens in a new tab)).

Gmail and Yahoo ask bulk senders for a record. Since February 1, 2024, Gmail (opens in a new tab) has required senders of more than 5,000 messages a day to Gmail accounts to set up SPF, DKIM and DMARC, and the DMARC policy can be set to none; from all senders, Google requires SPF or DKIM. Yahoo (opens in a new tab) requires bulk senders to implement both SPF and DKIM and to publish a valid DMARC policy of at least p=none, and strongly urges all senders to publish a DMARC policy for each domain that sends mail.

A p=none policy asks for no DMARC-specific action, and a discovered p=none policy must not change a receiver's existing mail handling. It does not guarantee delivery: what happens to a message still depends on the receiving system's own protection features.

How to publish a DMARC record

Before you start

Set up SPF, DKIM or both first: Google (opens in a new tab) requires SPF and/or DKIM before you can use DMARC, and asks you to allow 48 hours after setting them up. The SPF record generator builds an SPF record from the services that send email for your domain.

1. Choose where reports go

The rua tag in a DMARC record lists the addresses that receive aggregate reports (RFC 9989 section 4.7 (opens in a new tab)), and those reports show the sources of mail that use your domain (section 5.1.3 (opens in a new tab)). Google recommends a group or a dedicated mailbox to receive and manage them. If the report address is on a different domain, that domain must publish a TXT record authorizing the reports, or receivers do not send them; reporting services set this up for you.

2. Write the record

Domain owners usually start with p=none and a rua tag that points to the report mailbox (RFC 9989 section 5.1.4 (opens in a new tab)), and Google recommends a policy of none when you start using DMARC. This is the record DemiSignal's DMARC generator writes for that first step:

v=DMARC1; p=none; rua=mailto:[email protected]

Replace [email protected] with a working mailbox you control or your reporting service's address before publishing. The record starts with the v tag, followed by p.

3. Add it at your DNS host

Create the record at your domain registrar or DNS hosting service (Microsoft (opens in a new tab)):

Field Value
Type TXT
Host _dmarc (full name _dmarc.example.com)
Value v=DMARC1; p=none; rua=mailto:[email protected], with your own report address

Some domain hosts add the domain name automatically, so after you save, check that the record's name is formatted correctly. If you send from more than one domain, repeat these steps for each domain.

4. Check it

Run DemiSignal's check: it reads the public DNS records of the domain you enter and needs no account.

Checked a subdomain?

A lookup at a subdomain can come back empty while the subdomain is still covered by its parent's record. Live DNS answers for a subdomain and its parent:

Name TXT record
_dmarc.mail.google.com none (NXDOMAIN)
_dmarc.google.com v=DMARC1; p=reject; rua=mailto:[email protected]

Receivers take the domain from the message's From address (RFC 9989 section 5.3 (opens in a new tab)); when there is no record there, they look for the parent domain's record (section 4.10.1 (opens in a new tab)). In this example, the google.com record's p=reject applies to mail from mail.google.com, because that record sets no separate subdomain policy (an sp or np tag). A domain's DMARC record automatically covers all its subdomains that don't have their own record (Microsoft (opens in a new tab)).

If a checker reports no record for a subdomain, look up the parent domain before adding one.

Still not found after publishing?

  • The name is wrong. Some domain hosts add your domain to the host field automatically; check that the saved name is exactly _dmarc.example.com for your domain (Google (opens in a new tab)).
  • The record sits on the domain itself. Receivers query the name with _dmarc in front of the domain (RFC 9989 section 4.10.1 (opens in a new tab)), so a DMARC record on example.com is not where they look.
  • The version tag is missing or not first. Records that do not start with a v tag identifying the current DMARC version are discarded (RFC 9989 section 4.10 (opens in a new tab)).
  • There are two records. If a lookup returns more than one DMARC record, all of them are discarded.
  • DNS hasn't updated yet. DNS changes usually show within an hour, and some providers take up to 48 hours (SPF record generator).
  • The lookup failed. RFC 9989 separates a missing record from a transient DNS error, and DemiSignal's check reports an error rather than a fail when the DNS lookup did not complete; run it again.

Next: from monitoring to enforcement

The DMARC record generator builds a DMARC record one step at a time: start by monitoring, then enforce once your reports show your real senders pass. The DMARC policy not enabled guide covers the order for moving from p=none to quarantine or reject.

Sources

Tools for this

Frequently asked questions

What does No DMARC record found mean?

The checker did not find a DMARC record for the domain you entered. A subdomain may still be covered by its parent domain's policy. If receivers find no applicable policy, they do not apply DMARC to the message.

Do I need a DMARC record?

Gmail requires one from senders of more than 5,000 messages a day to Gmail accounts, Yahoo requires one from bulk senders, and both accept a policy of none. Yahoo strongly urges all senders to publish one for each domain that sends mail.

Which DMARC record should I publish first?

Start with one TXT record at _dmarc using p=none and a rua address for aggregate reports. Replace the example domain and report address with your own domain and a working mailbox before publishing.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.