DMARC

DMARC Checker

Inspect direct DMARC, SPF and optional DKIM DNS records with partial checks

DNS & Domain
🔒 100% client-side — your data never leaves this page
Maintained by Evan•Updated: September 30, 2026

Query direct mail DNS records with partial syntax and public-key structure checks. No email is sent; DMARC DNS Tree Walk, SPF recursive evaluation and DKIM signature verification are not performed. This is not an authentication result.

Query names

Manual queries send the domain and selector to Cloudflare DNS-over-HTTPS. At most 3 direct TXT queries, each with a 10-second timeout and 256 KiB response limit. The example runs locally. Input drafts are not saved; analytics excludes query names and records.

About this tool

DMARC Checker queries the direct _dmarc TXT name, domain TXT records for SPF, and an optional selector._domainkey TXT name through Cloudflare DNS-over-HTTPS. It joins character-strings within each TXT record, preserves separate records, distinguishes DNS errors from empty answers, and reports supported local tag and key-structure findings. DMARC checks reference RFC 9989; SPF checks cover the exact version, known mechanism names, basic delimiters and ip4/ip6 literals, while domain-spec, macro and recursive evaluation remain unchecked. DKIM checks cover tag syntax, required or revoked p, Base64, RSA PKCS#1/SPKI structures and Ed25519 byte length. It does not send email, perform DNS Tree Walk, discover organizational domains or selectors, authorize report destinations, evaluate alignment, prove usable keys or verify message signatures. Manual queries send the entered names to Cloudflare; the example uses local public fixtures and sends no queries. Input drafts are not saved. Each query has a 10-second timeout and 256 KiB response budget. Results are observations, not an authentication or deliverability verdict.

Failure Clinic (Common Pitfalls)

Treating p=none, a missing direct record, or a found DKIM key as an authentication verdict

Cause: DNS configuration is only part of mail processing. RFC 9989 uses DNS Tree Walk, and SPF/DKIM evaluation requires a sender identity or signed message.

Fix: Read these as local observations. The checker does not perform tree walking, message alignment, reporting authorization or signature verification.

Following an automatic none → quarantine → reject upgrade recipe

Cause: Policy choice depends on mail use and interoperability. RFC 9989 §7.4 advises general-purpose mail domains against p=reject.

Fix: Assess real mail flows and current standards before changing policy. Missing p has default/fallback rules; this tool does not calculate the final receiver policy.

Calling Base64 a valid usable key

Cause: Encoding, DER structure or Ed25519 byte length do not prove key ownership, cryptographic validity or an authentic signature.

Fix: Use the reported structure as a limited check. Unknown DKIM tags/key types and SPF domain-spec/macros are explicitly left unevaluated.

Scenario Recipes

01

Inspect a direct mail DNS record without claiming authentication

Goal: Separate what a resolver returned from what a mail receiver would decide.

  1. Enter an ASCII domain, using punycode for an internationalized name. Add the selector from the s= value of a DKIM-Signature header only when it is known.
  2. Query Cloudflare DNS-over-HTTPS and inspect each direct name, TTL, raw TXT presentation and joined record. A DNS failure is separate from an empty answer.
  3. Review multiple records, supported tags and key-structure findings. Use a mail receiver or dedicated authentication workflow for tree-walk policy discovery, SPF identity evaluation and DKIM message signatures.

Result: A time-stamped direct-record observation. It does not establish deliverability, effective DMARC policy or successful authentication.

Production Snippets

TXT chunks belong to one DNS record

text

_dmarc.example.test. IN TXT "v=DM" "ARC1; p=none"

One RR joins to: v=DMARC1; p=none
There is no inserted space between the character-strings.
Two separate TXT RRs remain two records and must not be joined.

Frequently Asked Questions

Does this verify that mail passes authentication?

No. Direct DNS observations do not evaluate sender identity, DMARC alignment or a DKIM message signature. Finding a record or a key structure is not an authentication pass.

Does it discover a parent DMARC policy?

No. RFC 9989 uses DNS Tree Walk for policy and organizational-domain discovery; this tool only queries the direct name. A missing direct record does not establish that no policy applies.

Is p=none or missing p always a failure?

No. p=none is a valid policy, and RFC 9989 has default and valid-rua fallback rules for missing or invalid policy fields. This tool reports fields and local findings without calculating the final receiver policy. General-purpose mail domains should not automatically progress to p=reject.

How is an optional DKIM selector obtained?

Use the s= value in a real DKIM-Signature header or the mail provider’s documentation. The tool does not enumerate or guess selectors.

Why are multiple TXT records treated separately?

Strings inside one TXT record are joined without an added space. Separate records remain separate: multiple SPF records produce permerror, multiple DMARC candidates are discarded, and multiple DKIM selector records have undefined results.

Where is input processed?

Manual lookups send domain and selector names to Cloudflare DNS-over-HTTPS. Returned records are checked in the browser. The example is fully local, drafts are not saved, and analytics excludes names and records.

Keep browsing