DMARC & SPF Record Generator

Generate compliant DMARC and SPF DNS TXT records for Google Workspace, Microsoft 365, and transactional email providers.

DMARC Enforcement & Reporting Policy (RFC 7489)
Where daily XML delivery reports are sent
Policy Enforcement Percentage (pct=)100%
Generated DNS TXT Entry (Copy into Cloudflare, GoDaddy, Namecheap)
Record Type:TXT
Host / Name:_dmarc.example.com
Value / Content:v=DMARC1; p=quarantine; rua=mailto:dmarc-reports@example.com

The Pillars of Modern Email Deliverability

Email remains the backbone of internet communication and commerce, yet SMTP was originally designed without identity verification. Implementing cryptographic DKIM signatures, SPF IP authorizations, and DMARC enforcement policies closes the loop on sender verification, protecting your brand reputation and guaranteeing top-tier inbox delivery rates.

Infrastructure Applications

  • Google & Yahoo Mandatory 2024 Email Compliance

    Fulfill the strict email sender guidelines introduced by Google Gmail and Yahoo Mail requiring valid SPF, DKIM, and DMARC records for all outbound domains.

  • Domain Anti-Spoofing & Phishing Defense

    Prevent malicious bad actors from impersonating your corporate domain (`@yourcompany.com`) in business email compromise (BEC) wire transfer scams.

  • B2B Sales Outbound & Cold Email Deliverability

    Safeguard primary and secondary sales domains against landing in spam folders when sending transactional receipts, marketing blasts, or client onboarding emails.

  • Google Workspace & Microsoft 365 Domain Setup

    Authorize official cloud mailboxes alongside third-party transactional mail services (SendGrid, Mailgun, Postmark, AWS SES) within a single unified SPF string.

Key Capabilities

Dual DMARC & SPF Generators

Seamlessly switch between generating RFC 7489 DMARC policy tags and RFC 7208 SPF mechanism authorization strings.

Granular Policy Controls

Configure `none` (monitoring), `quarantine` (spam classification), or `reject` (hard bounce drop) alongside `pct=` rollout percentages.

One-Click ESP Inclusions

Pre-configured includes for Google Workspace (`include:_spf.google.com`), Microsoft 365 (`include:spf.protection.outlook.com`), SendGrid, and Amazon SES.

DNS Host Copy-Ready Formatting

Formats exact Host/Name (e.g. `_dmarc.yourdomain.com`) and TXT Values ready to paste into Cloudflare, GoDaddy, Namecheap, or Route 53.

Frequently Asked Questions

What is DMARC and why is it now required?

DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that uses SPF and DKIM to determine the authenticity of an email message. In 2024, Google and Yahoo made DMARC mandatory for all organizations sending bulk emails to protect users from phishing and spam.

What is the difference between p=none, p=quarantine, and p=reject?

`p=none` is monitoring mode: failed emails are still delivered normally, but XML reports are sent to your `rua` email. `p=quarantine` instructs receiving mail servers to send failed messages directly to the recipient's Spam/Junk folder. `p=reject` instructs servers to completely reject and block unauthenticated messages at the SMTP gateway.

Why should a domain have only ONE SPF record?

RFC 7208 explicitly specifies that a domain MUST NOT have more than one SPF TXT record. If a domain publishes multiple SPF records, receiving mail servers will trigger a `PermError` (Permanent Error) and fail authentication entirely. All mail services must be combined inside a single `v=spf1 ...` record.

What is the 10 DNS lookup limit in SPF?

The SPF specification limits the number of mechanisms that require DNS lookups (such as `include`, `a`, `mx`, and `redirect`) to a maximum of 10. Exceeding 10 DNS lookups triggers an SPF PermError.

ARCADE BRAIN BREAK

Need a Brain Break? ☕

Done working on your task? Take a quick 60-second break, test your reflexes, and flap through infinite pixel obstacles in Sky Flap!

Instant Browser Play High Score Tracker