Live DNS check · same engine as the full SecLens score

DMARC checker

DMARC tells receiving mail servers what to do with messages that fail SPF or DKIM for your domain. A published record is not protection by itself. This checker reads the live _dmarc TXT, then scores policy (p=), subdomain policy (sp=), coverage (pct=), and syntax. Monitoring mode (p=none) scores zero on this scale.

Public assessments are free. No account. The full 0–100 stack is included below the focused result.

63.5%
of mail-enabled Top-1M domains publish DMARC
29.0%
enforce quarantine or reject

Figures from the July 2026 Top-1M study.

FAQ

Common questions

What is DMARC?

DMARC is a DNS policy at _dmarc.example.com that tells receivers what to do when mail fails SPF or DKIM alignment. The p= tag is the action: none (monitor), quarantine (spam folder), or reject (block). SecLens scores the live policy, not the mere presence of a record.

What is the difference between p=none and p=reject?

p=none asks receivers to take no action on failures. It is useful while you watch reports, and it scores 0 points here. p=quarantine asks them to treat failures as spam (15 points when pct is 100). p=reject asks them to refuse the message (25 points when pct is 100).

Does a DMARC record alone protect me?

No. A record with p=none, a syntax error, or pct=0 does not stop spoofing. Receivers only enforce what the policy asks. This checker reports policy, coverage, syntax, and whether aggregate reporting is configured, then still runs the rest of the email-security stack.

Scoring rules are on the methodology page. The homepage still has the full product, including the live Pulse.