How to Set Up DMARC in 10 Minutes (Step-by-Step Guide)
How to Set Up DMARC in 10 Minutes — Step by Step for Every Major Domain Registrar
Gmail and Yahoo now require DMARC for bulk senders. Without it, your emails land in spam or get rejected entirely. Setting up DMARC sounds technical, but it takes 10 minutes once you know what to do.
This guide covers exact steps for GoDaddy, Namecheap, Cloudflare, Google Domains, and generic DNS providers.
What DMARC Actually Does
DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells email providers what to do when your SPF or DKIM authentication fails.
Without DMARC:
- Spammers can impersonate your domain
- ISPs don't know if authentication failures are your problem or an attack
- Your legitimate emails get treated with suspicion
With DMARC:
- You specify how to handle authentication failures (reject, quarantine, or monitor)
- You receive reports about who's sending email from your domain
- ISPs trust your emails more because you're taking security seriously
Before You Start: Prerequisites
You need SPF and DKIM set up first. DMARC won't work without them.
Check if you have SPF:
nslookup -type=TXT yourdomain.com
Look for a record starting with v=spf1.
Check if you have DKIM:
Send yourself a test email. View the full headers. Look for DKIM-Signature: v=1.
If either is missing, set those up first. DMARC depends on them.
The DMARC Record Explained
A basic DMARC record looks like this:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
Breaking it down:
v=DMARC1- Version (always this)p=none- Policy: what to do with failing emails
none = monitor only (recommended for first 1-2 weeks)
- quarantine = send to spam folder
- reject = block the email entirely
rua=mailto:your@email.com- Where to send aggregate reports
More advanced options:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; ruf=mailto:forensics@yourdomain.com; pct=100; adkim=r; aspf=r
ruf- Forensic reports (detailed failure reports)pct- Percentage of emails to apply policy to (100 = all emails)adkim- DKIM alignment mode (r=relaxed, s=strict)aspf- SPF alignment mode (r=relaxed, s=strict)
Start simple. Add complexity later if needed.
Step-by-Step: GoDaddy
1. Log into GoDaddy
2. Go to My Products → Domains
3. Click your domain → DNS button
4. Scroll to Records section
5. Click Add button
6. Select record type: TXT
7. Fill in:
- Name: _dmarc
- Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
- TTL: 600 (10 minutes)
8. Click Save
GoDaddy automatically appends your domain name, so just enter _dmarc not _dmarc.yourdomain.com.
Wait 10-30 minutes for propagation. Test at checkyouremail.online.
Step-by-Step: Namecheap
1. Log into Namecheap
2. Go to Domain List → click Manage on your domain
3. Go to Advanced DNS tab
4. Click Add New Record
5. Select TXT Record
6. Fill in:
- Host: _dmarc
- Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
- TTL: Automatic
7. Click the green checkmark to save
Namecheap propagates quickly, usually within 10 minutes.
Verify setup → checkyouremail.online
Step-by-Step: Cloudflare
1. Log into Cloudflare
2. Select your domain
3. Go to DNS section
4. Click Add record
5. Fill in:
- Type: TXT
- Name: _dmarc
- Content: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
- TTL: Auto
- Proxy status: DNS only (gray cloud)
6. Click Save
Cloudflare's interface is clean and obvious. Make sure the cloud icon is gray (DNS only), not orange (proxied).
Test after 5-10 minutes → checkyouremail.online
Step-by-Step: Google Domains (Now Squarespace)
Google Domains was acquired by Squarespace in 2023. If you're still using the old interface:
1. Go to domains.google.com
2. Click your domain
3. Go to DNS section
4. Scroll to Custom resource records
5. Add new record:
- Name: _dmarc
- Type: TXT
- TTL: 3600
- Data: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
6. Click Add
If you've migrated to Squarespace domains, the process is similar but the interface is slightly different.
Step-by-Step: Generic DNS Provider
Can't find your provider above? The concept is the same everywhere:
1. Log into your DNS management panel
2. Find where you add DNS records (usually called "DNS Management," "DNS Settings," or "Zone File")
3. Add a new TXT record
4. Host/Name: _dmarc or _dmarc.yourdomain.com (depends on provider)
5. Value: v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com
6. TTL: 3600 or whatever the default is
7. Save
Some providers automatically append the domain name, others don't. If you're unsure, try both ways and check which one works.
Verify Your DMARC Record
Wait 10-30 minutes after adding the record. DNS changes aren't instant.
Check via command line:
nslookup -type=TXT _dmarc.yourdomain.com
You should see your DMARC record in the response.
Check via online tools:
Use checkyouremail.online for a complete check including DMARC validation, SPF alignment, and DKIM verification.
Common DMARC Mistakes and How to Fix Them
Mistake 1: Missing underscore prefix
Wrong: dmarc.yourdomain.com
Right: _dmarc.yourdomain.com
The underscore is mandatory. Without it, ISPs won't find your DMARC record.
Mistake 2: Multiple DMARC records
You can only have one DMARC record per domain. If you see multiple when you check, delete the extras.
Mistake 3: Invalid email address in rua
Wrong: rua=dmarc@yourdomain.com (missing mailto:)
Right: rua=mailto:dmarc@yourdomain.com
The mailto: prefix is required. Without it, reports won't be delivered.
Mistake 4: Typos in the policy tag
Wrong: p=reject; (semicolon after value)
Right: p=reject (no semicolon unless another tag follows)
Wrong: p=quarentine (misspelled)
Right: p=quarantine
Copy-paste the examples in this guide to avoid typos.
Mistake 5: Starting with p=reject
Don't jump straight to p=reject on day one. You'll block legitimate emails if your SPF or DKIM isn't properly configured.
Proper progression:
Week 1-2: p=none (monitor mode)
- Collect reports
- Verify legitimate emails are passing
- Identify any authentication issues
Week 3-4: p=quarantine (spam folder for failures)
- Monitor impact
- Make sure important emails still deliver
Week 5+: p=reject (block failures entirely)
- Maximum protection
- Only after confirming no legitimate emails fail
Test at each stage → checkyouremail.online
Understanding DMARC Reports
Once your DMARC record is active, you'll start receiving aggregate reports (rua) at the email address you specified.
These reports are XML files that look confusing but contain valuable data:
- Who's sending email from your domain
- Which emails passed/failed SPF and DKIM
- Volume of emails sent
- Percentage of authentication success
Example report interpretation:
203.0.113.10
150
pass
pass
This shows 150 emails were sent from IP 203.0.113.10 and passed both SPF and DKIM. Good.
If you see failures, investigate:
- Is this a legitimate server you forgot to include in SPF?
- Is someone impersonating your domain?
- Is your DKIM signature broken?
Parse reports easily:
Tools like Dmarcian, Postmark's DMARC digest, or MxToolbox can parse these XML reports into readable dashboards.
DMARC for Subdomains
By default, your DMARC policy applies to all subdomains. But you can set specific policies for subdomains.
Main domain:
_dmarc.yourdomain.com → v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com
Subdomain with different policy:
_dmarc.marketing.yourdomain.com → v=DMARC1; p=quarantine; rua=mailto:marketing-dmarc@yourdomain.com
This is useful if you:
- Send marketing from a subdomain
- Use different authentication for different purposes
- Want to be more lenient with certain subdomains
DMARC and Third-Party Senders
If you use services like Mailchimp, SendGrid, or HubSpot to send emails on your behalf, DMARC can break things if not configured correctly.
The problem:
These services send from their servers but use your domain in the "From" address. DMARC checks if the sending server is authorized by your SPF record.
The solution:
Make sure your SPF record includes the third-party service:
v=spf1 include:_spf.google.com include:sendgrid.net include:servers.mcsv.net -all
Also ensure the service is configured to sign emails with DKIM using your domain.
Most reputable services have detailed DMARC setup guides. Follow them carefully.
Test after adding third-party services → checkyouremail.online
Upgrading from p=none to p=reject
After monitoring for 1-2 weeks with p=none, you should have enough data to upgrade.
Check your reports:
- Are all legitimate emails passing SPF and DKIM?
- Have you identified all authorized senders?
- Are there any unexplained failures?
If yes to #1 and #2, and no to #3, upgrade:
Step 1: p=quarantine at 10%
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=10
This applies the quarantine policy to only 10% of emails. Monitor for issues.
Step 2: p=quarantine at 100%
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100
After a week with no problems, apply to all emails.
Step 3: p=reject
v=DMARC1; p=reject; rua=mailto:dmarc@yourdomain.com; pct=100
Maximum protection. Failed emails are completely blocked.
What Happens After DMARC Is Set Up
Immediate effects:
- Gmail, Outlook, Yahoo start checking your DMARC policy
- You receive aggregate reports (usually daily)
- Your domain security improves
- Phishing attempts using your domain are blocked (once you reach p=reject)
Within 1-2 weeks:
- Improved inbox placement rates
- Better sender reputation
- Fewer spam complaints (because spammers can't impersonate you)
Long-term benefits:
- Protection against domain spoofing
- Visibility into all email sent from your domain
- Compliance with industry requirements
- Higher deliverability rates
Troubleshooting DMARC Issues
Problem: No reports arriving
- Check the email address in rua is correct
- Make sure it includes
mailto: - Wait 24-48 hours (reports aren't instant)
- Check spam folder for XML attachments
Problem: Legitimate emails failing
- Review SPF record for missing authorized servers
- Check DKIM is properly configured
- Verify alignment between From domain and authenticated domain
- Temporarily switch back to
p=nonewhile investigating
Problem: DMARC record not found
- Confirm you used
_dmarcnotdmarc - Wait longer for DNS propagation (can take up to 48 hours)
- Check for typos in the record
- Try adding the full hostname:
_dmarc.yourdomain.com
Run a comprehensive check at checkyouremail.online to identify specific issues.
DMARC Checklist
- [ ] SPF record exists and includes all authorized senders
- [ ] DKIM is configured and signing emails
- [ ] Added DMARC TXT record at
_dmarc.yourdomain.com - [ ] Started with
p=nonepolicy - [ ] Included valid email address in rua tag
- [ ] Verified record with DNS lookup
- [ ] Sent test emails and checked headers
- [ ] Waiting for aggregate reports
- [ ] Monitored for 1-2 weeks
- [ ] Upgraded to
p=quarantinethenp=reject - [ ] Tested final configuration
Your DMARC setup is complete. You've closed a major security hole and improved your email deliverability at the same time.
Run a free deliverability check right now at checkyouremail.online — no signup, results in 30 seconds.