DMARC & SPF Record Generator
Generate compliant DMARC and SPF DNS TXT records for Google Workspace, Microsoft 365, and transactional email providers.
The Pillars of Modern Email Deliverability
Email remains the backbone of internet communication and commerce, yet SMTP was originally designed without identity verification. Implementing cryptographic DKIM signatures, SPF IP authorizations, and DMARC enforcement policies closes the loop on sender verification, protecting your brand reputation and guaranteeing top-tier inbox delivery rates.
Infrastructure Applications
- ✓Google & Yahoo Mandatory 2024 Email Compliance
Fulfill the strict email sender guidelines introduced by Google Gmail and Yahoo Mail requiring valid SPF, DKIM, and DMARC records for all outbound domains.
- ✓Domain Anti-Spoofing & Phishing Defense
Prevent malicious bad actors from impersonating your corporate domain (`@yourcompany.com`) in business email compromise (BEC) wire transfer scams.
- ✓B2B Sales Outbound & Cold Email Deliverability
Safeguard primary and secondary sales domains against landing in spam folders when sending transactional receipts, marketing blasts, or client onboarding emails.
- ✓Google Workspace & Microsoft 365 Domain Setup
Authorize official cloud mailboxes alongside third-party transactional mail services (SendGrid, Mailgun, Postmark, AWS SES) within a single unified SPF string.
Key Capabilities
Dual DMARC & SPF Generators
Seamlessly switch between generating RFC 7489 DMARC policy tags and RFC 7208 SPF mechanism authorization strings.
Granular Policy Controls
Configure `none` (monitoring), `quarantine` (spam classification), or `reject` (hard bounce drop) alongside `pct=` rollout percentages.
One-Click ESP Inclusions
Pre-configured includes for Google Workspace (`include:_spf.google.com`), Microsoft 365 (`include:spf.protection.outlook.com`), SendGrid, and Amazon SES.
DNS Host Copy-Ready Formatting
Formats exact Host/Name (e.g. `_dmarc.yourdomain.com`) and TXT Values ready to paste into Cloudflare, GoDaddy, Namecheap, or Route 53.
Frequently Asked Questions
What is DMARC and why is it now required?
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that uses SPF and DKIM to determine the authenticity of an email message. In 2024, Google and Yahoo made DMARC mandatory for all organizations sending bulk emails to protect users from phishing and spam.
What is the difference between p=none, p=quarantine, and p=reject?
`p=none` is monitoring mode: failed emails are still delivered normally, but XML reports are sent to your `rua` email. `p=quarantine` instructs receiving mail servers to send failed messages directly to the recipient's Spam/Junk folder. `p=reject` instructs servers to completely reject and block unauthenticated messages at the SMTP gateway.
Why should a domain have only ONE SPF record?
RFC 7208 explicitly specifies that a domain MUST NOT have more than one SPF TXT record. If a domain publishes multiple SPF records, receiving mail servers will trigger a `PermError` (Permanent Error) and fail authentication entirely. All mail services must be combined inside a single `v=spf1 ...` record.
What is the 10 DNS lookup limit in SPF?
The SPF specification limits the number of mechanisms that require DNS lookups (such as `include`, `a`, `mx`, and `redirect`) to a maximum of 10. Exceeding 10 DNS lookups triggers an SPF PermError.
More Developer Tools
Need a Brain Break? ☕
Done working on your task? Take a quick 60-second break, test your reflexes, and flap through infinite pixel obstacles in Sky Flap!