Build a DMARC policy TXT record with reporting addresses.
Tip: use samples, upload, copy, download, and send-to actions inside the workspace where available.
DMARC Record Generator is a free, browser-based tool that helps you produce ready-to-use output in seconds. Build a DMARC policy TXT record with reporting addresses. It's built for speed and privacy: Everything runs locally in your browser — your data is never uploaded to a server. No sign-up, no installs, and no daily limits.
Generate a sample or helper artifact, then copy it into the workflow that needs it.
Review the preview, copy or download the result, and keep everything local in your browser.
SPF Record Generator: Build a valid SPF TXT record from your senders and policy.
Open toolDKIM Key Generator: Generate an RSA-2048 DKIM key pair and DNS record in your browser.
Open toolEmail Header Analyzer: Parse raw email headers — SPF/DKIM/DMARC results and delivery hops.
Open tool| Stage | Record | Timing | Why |
|---|---|---|---|
| 1. Monitor | p=none, pct=100 | Weeks 1–4 | Collect aggregate reports. Change nothing else. Identify every legitimate sender before enforcing anything. |
| 2. Quarantine 10% | p=quarantine, pct=10 | Weeks 5–6 | First enforcement. 10% of failing mail goes to spam, limiting the damage if you missed a sender. |
| 3. Quarantine 50% | p=quarantine, pct=50 | Weeks 7–8 | Ramp up once reports stay clean. Watch for complaints from internal teams using shadow-IT senders. |
| 4. Quarantine 100% | p=quarantine, pct=100 | Weeks 9–12 | All failing mail is quarantined. Legitimate mail is recoverable from spam, so this is the safe plateau. |
| 5. Reject 100% | p=reject, pct=100 | Week 13+ | Full protection. Spoofed mail is refused at SMTP time and never reaches a mailbox. |