No DMARC record found
Fix No DMARC record found: add the right DNS TXT record, check subdomain inheritance, and troubleshoot a record that still does not appear.
On this page
"No DMARC record found" means the checker did not find a DMARC record for the domain you entered (MXToolbox (opens in a new tab)). If you checked a subdomain, first see whether its parent domain's policy covers it (RFC 9989 section 4.10.1 (opens in a new tab)). If no policy applies, publish one DNS (Domain Name System) TXT (text) record (opens in a new tab) at _dmarc.example.com, with your domain in place of example.com, start at p=none with a reporting address, and check again.
What the message means
RFC 9989 (opens in a new tab), which obsoletes RFC 7489, defines DMARC (Domain-based Message Authentication, Reporting, and Conformance). A domain's DMARC record is a TXT record in DNS at the name made by putting the label _dmarc in front of the domain (section 4.1 (opens in a new tab)). MXToolbox (opens in a new tab) shows this message when your domain does not have a published DMARC record.
Receivers look in the same place. They take the domain from the message's From address (section 5.3 (opens in a new tab)) and query _dmarc in front of it; if no valid record is there, they look for the record of its parent domain (section 4.10.1 (opens in a new tab)). If they find no record at all, DMARC does not apply to the message.
DemiSignal's check flags a missing DMARC record too. It reports a fail when the record is missing or broken, and an error when the DNS lookup did not complete, in which case run the check again.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.
Does it affect your email?
DMARC builds on two other checks. Sender Policy Framework (SPF) (opens in a new tab) lets the owner of the MAIL FROM (envelope sender) domain publish which hosts may use it, and receivers test the sending server against that list. DomainKeys Identified Mail (DKIM) (opens in a new tab) signs some or all of a message so receivers can confirm the signed content has not changed. To pass DMARC, a message needs an SPF or DKIM pass for a domain aligned with the domain in its From address (RFC 9989 section 1 (opens in a new tab)). For messages that fail, the DMARC policy tells receivers what to do: reject, quarantine or no instruction (Microsoft (opens in a new tab)).
Without an applicable DMARC record, receivers have no DMARC policy from you to apply, and the final handling of your mail stays with each receiver's own policies (RFC 9989 section 5.4 (opens in a new tab)). In Microsoft 365, the dmarc result in a message's Authentication-Results header can then be bestguesspass: no DMARC record exists for the sender's domain, and Microsoft 365 inferred a pass using heuristics (Microsoft (opens in a new tab)).
Gmail and Yahoo ask bulk senders for a record. Since February 1, 2024, Gmail (opens in a new tab) has required senders of more than 5,000 messages a day to Gmail accounts to set up SPF, DKIM and DMARC, and the DMARC policy can be set to none; from all senders, Google requires SPF or DKIM. Yahoo (opens in a new tab) requires bulk senders to implement both SPF and DKIM and to publish a valid DMARC policy of at least p=none, and strongly urges all senders to publish a DMARC policy for each domain that sends mail.
A p=none policy asks for no DMARC-specific action, and a discovered p=none policy must not change a receiver's existing mail handling. It does not guarantee delivery: what happens to a message still depends on the receiving system's own protection features.
How to publish a DMARC record
Before you start
Set up SPF, DKIM or both first: Google (opens in a new tab) requires SPF and/or DKIM before you can use DMARC, and asks you to allow 48 hours after setting them up. The SPF record generator builds an SPF record from the services that send email for your domain.
1. Choose where reports go
The rua tag in a DMARC record lists the addresses that receive aggregate reports (RFC 9989 section 4.7 (opens in a new tab)), and those reports show the sources of mail that use your domain (section 5.1.3 (opens in a new tab)). Google recommends a group or a dedicated mailbox to receive and manage them. If the report address is on a different domain, that domain must publish a TXT record authorizing the reports, or receivers do not send them; reporting services set this up for you.
2. Write the record
Domain owners usually start with p=none and a rua tag that points to the report mailbox (RFC 9989 section 5.1.4 (opens in a new tab)), and Google recommends a policy of none when you start using DMARC. This is the record DemiSignal's DMARC generator writes for that first step:
v=DMARC1; p=none; rua=mailto:[email protected]
Replace [email protected] with a working mailbox you control or your reporting service's address before publishing. The record starts with the v tag, followed by p.
3. Add it at your DNS host
Create the record at your domain registrar or DNS hosting service (Microsoft (opens in a new tab)):
| Field | Value |
|---|---|
| Type | TXT |
| Host | _dmarc (full name _dmarc.example.com) |
| Value | v=DMARC1; p=none; rua=mailto:[email protected], with your own report address |
Some domain hosts add the domain name automatically, so after you save, check that the record's name is formatted correctly. If you send from more than one domain, repeat these steps for each domain.
4. Check it
Run DemiSignal's check: it reads the public DNS records of the domain you enter and needs no account.
Checked a subdomain?
A lookup at a subdomain can come back empty while the subdomain is still covered by its parent's record. Live DNS answers for a subdomain and its parent:
| Name | TXT record |
|---|---|
_dmarc.mail.google.com |
none (NXDOMAIN) |
_dmarc.google.com |
v=DMARC1; p=reject; rua=mailto:[email protected] |
Receivers take the domain from the message's From address (RFC 9989 section 5.3 (opens in a new tab)); when there is no record there, they look for the parent domain's record (section 4.10.1 (opens in a new tab)). In this example, the google.com record's p=reject applies to mail from mail.google.com, because that record sets no separate subdomain policy (an sp or np tag). A domain's DMARC record automatically covers all its subdomains that don't have their own record (Microsoft (opens in a new tab)).
If a checker reports no record for a subdomain, look up the parent domain before adding one.
Still not found after publishing?
- The name is wrong. Some domain hosts add your domain to the host field automatically; check that the saved name is exactly
_dmarc.example.comfor your domain (Google (opens in a new tab)). - The record sits on the domain itself. Receivers query the name with
_dmarcin front of the domain (RFC 9989 section 4.10.1 (opens in a new tab)), so a DMARC record onexample.comis not where they look. - The version tag is missing or not first. Records that do not start with a
vtag identifying the current DMARC version are discarded (RFC 9989 section 4.10 (opens in a new tab)). - There are two records. If a lookup returns more than one DMARC record, all of them are discarded.
- DNS hasn't updated yet. DNS changes usually show within an hour, and some providers take up to 48 hours (SPF record generator).
- The lookup failed. RFC 9989 separates a missing record from a transient DNS error, and DemiSignal's check reports an error rather than a fail when the DNS lookup did not complete; run it again.
Next: from monitoring to enforcement
The DMARC record generator builds a DMARC record one step at a time: start by monitoring, then enforce once your reports show your real senders pass. The DMARC policy not enabled guide covers the order for moving from p=none to quarantine or reject.
Sources
- MXToolbox: DMARC Record Published (opens in a new tab)
- RFC 9989 (RFC Editor information page) (opens in a new tab)
- RFC 9989 section 1: Introduction (opens in a new tab)
- RFC 9989 section 4.1: DMARC Basics (opens in a new tab)
- RFC 9989 section 4.7: DMARC Policy Record Format (opens in a new tab)
- RFC 9989 section 4.10: DNS Tree Walk (opens in a new tab)
- RFC 9989 section 4.10.1: DMARC Policy Discovery (opens in a new tab)
- RFC 9989 section 5.1.3: Set Up a Mailbox to Receive Aggregate Reports (opens in a new tab)
- RFC 9989 section 5.1.4: Publish a DMARC Policy Record (opens in a new tab)
- RFC 9989 section 5.3: Mail Receiver Actions (opens in a new tab)
- RFC 9989 section 5.4: Policy Enforcement Considerations (opens in a new tab)
- RFC 7208: Sender Policy Framework (SPF), section 1 (opens in a new tab)
- RFC 6376: DomainKeys Identified Mail (DKIM) Signatures, section 1 (opens in a new tab)
- Microsoft: Set up DMARC to validate email in Microsoft 365 (opens in a new tab)
- Microsoft: Troubleshoot email authentication in Microsoft 365 (opens in a new tab)
- Google: Email sender guidelines (opens in a new tab)
- Google Workspace: Set up DMARC (opens in a new tab)
- Google Workspace: About TXT records (opens in a new tab)
- Yahoo: Sender best practices (opens in a new tab)
- DemiSignal: SPF, DKIM and DMARC check
- DemiSignal: SPF record generator
- DemiSignal: DMARC record generator
- DemiSignal: DMARC policy not enabled
Tools for this
-
SPF, DKIM and DMARC check
Check the email records a domain publishes today and see what to fix first.
-
DMARC record generator
Build a DMARC record step by step, from monitoring to reject.
Frequently asked questions
What does No DMARC record found mean?
The checker did not find a DMARC record for the domain you entered. A subdomain may still be covered by its parent domain's policy. If receivers find no applicable policy, they do not apply DMARC to the message.
Do I need a DMARC record?
Gmail requires one from senders of more than 5,000 messages a day to Gmail accounts, Yahoo requires one from bulk senders, and both accept a policy of none. Yahoo strongly urges all senders to publish one for each domain that sends mail.
Which DMARC record should I publish first?
Start with one TXT record at _dmarc using p=none and a rua address for aggregate reports. Replace the example domain and report address with your own domain and a working mailbox before publishing.
Check your domain now
See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.