DMARC Policy Analyzer & Alignment Inspector
Audit DMARC records at _dmarc.<domain>, verify p=reject enforcement, check organizational inheritance, and inspect aggregate reporting.
How DMARC Policy Analyzer Works
TXT Query at _dmarc
Queries `_dmarc.<domain>` for TXT records starting with `v=DMARC1`.
Policy Enforcement Audit
Evaluates the `p=` parameter (`none` = monitoring only, `quarantine` = spam folder, `reject` = block outright).
Reporting Tag Verification
Validates `rua` and `ruf` mailto addresses to confirm aggregate forensic telemetry is active.
RFC Engineering Standards
Every check performed by this tool adheres strictly to the Internet Engineering Task Force (IETF) Request for Comments:
- RFC 7489 (DMARC Policy & Reporting)
- RFC 7960 (Interoperability Guidelines)
Common Issues & How to Fix Them
If our diagnostic discovers configuration anomalies, use the remediation steps below:
Remediation: A policy of `p=none` only monitors and does not protect against domain impersonation. Progress toward `p=quarantine` and ultimately `p=reject`.
Remediation: Add `rua=mailto:dmarc-reports@yourdomain.com` to receive XML telemetry on who is sending mail from your domain.
Frequently Asked Questions
Why did Google and Yahoo make DMARC mandatory in 2024–2026?
To prevent phishing, brand impersonation, and fraudulent emails. High-volume senders without an active DMARC policy face outright rejections and deferred delivery across consumer inboxes.
What is the difference between p=none, p=quarantine, and p=reject?
p=none monitors traffic without interfering with delivery; p=quarantine routes failed emails directly to the recipient's spam folder; p=reject instructs recipient servers to drop unauthenticated emails at the SMTP socket.
Explore Other Free Diagnostic Tools
MX Record Lookup
Discover active Mail Exchanger (MX) hosts, priority rankings, IPv4/IPv6 addresses, and Null MX configurations in real-time.
SPF Record Validator
Validate Sender Policy Framework syntax, recursively trace include trees, and safeguard against the strict 10-lookup DNS limit.
DKIM Key Checker
Probe over 45 industry-standard DKIM selectors, inspect public RSA/Ed25519 cryptographic keys, and confirm cryptographic strength.
Disposable Domain Checker
Check any domain against BounceLayer's in-memory list of over 100,000 throwaway, temporary, and 10-minute inbox services.
Email Checker
Instant keyless diagnostic inspecting RFC 5322 syntax grammar, authoritative MX records, role accounts, and free email providers.
Blacklist Checker
Scan IPv4 addresses and domains against authoritative DNS blocklists (Spamhaus, Barracuda, SORBS, SURBL, SpamCop) in parallel.
Verify Real Mailbox Existence in Real-Time
DNS tests only tell you if a server is reachable. BounceLayer's API connects directly to recipient mail servers via port 25 SMTP handshakes to confirm exact mailbox existence in under 140ms.