LESS GUESSWORK. CLEARER ANSWERS.
DMARC checker
Inspect the DMARC record and core policy tags at the exact domain. Inherited policy and message alignment are not checked.
Your domain is sent to our server and Google Public DNS. SSL checks also make a TLS connection to one public server on port 443. We do not save a report history.
A clear view of your configuration
Run a check to see what was found, when it was checked and what needs attention.
A snapshot, with context
Results reflect one resolver and, for SSL, one server. Network failures are shown separately from missing or invalid records. Checked times display in your timezone.
Know what a check can tell you
One resolver and one TLS endpoint do not prove global DNS propagation, overall security or email deliverability. Certificate revocation is not checked. Email-record inspection is limited: no recursive SPF evaluation, organizational-domain DMARC fallback, external reporting authorization or signed-message DKIM verification. A 12-second deadline, bounded DNS responses, four concurrent server checks and request limits apply. Cancelling hides a report; already-started server work may finish within its deadline.