No DMARC record found

Publish a DMARC record the right way, and start getting reports before you enforce.

What you are seeing

  • No DMARC record found for example.com
  • DMARC record published: Failed
  • dmarc=none (p=NONE) header.from=example.com

Just the part after the @. Free, no sign-up, and the result gets a shareable link.

What it means

DMARC lives in a TXT record at `_dmarc.<yourdomain>`. "No DMARC record found" means that exact name returned no TXT record starting with `v=DMARC1`.

Without DMARC, receivers have no instruction about unauthenticated mail claiming to be from you, and you get no reports about who is sending as your domain. Gmail and Yahoo require bulk senders to publish one.

Missing DMARC is not the same as failing DMARC. A missing record reports as `dmarc=none` because there is no policy to apply, so nothing is quarantined — and nothing is visible either.

Why it happens

It was never published
The common case. SPF and DKIM get set up during mail migration; DMARC is a separate record nobody is prompted to add.
It is on the wrong name
The record must be at `_dmarc.example.com`, not on the root domain and not at `dmarc.example.com`. A DMARC policy published on the apex does nothing.
The host field got the domain appended
Entering `_dmarc.example.com` in a panel that appends the zone creates `_dmarc.example.com.example.com`. Enter only `_dmarc`.
Two DMARC records exist
More than one `v=DMARC1` TXT record at `_dmarc` makes the policy unusable, and many tools report that as no record found.
The record is there but syntactically invalid
`v=DMARC1` must come first, tags are semicolon-separated, and an unknown or malformed tag before `p=` can make the whole record be discarded.
You are checking a subdomain
Subdomains inherit the organisational domain's policy, or its `sp=` value, without having their own record. A lookup against the subdomain name alone reports nothing.

How to fix it

  1. 1Get SPF and DKIM working first. DMARC only reports on alignment, so publishing it before SPF and DKIM are in place produces alarming reports and no benefit. Run the full check above to see where you stand.
  2. 2Publish a monitoring record. Add a TXT record with host `_dmarc` and value `v=DMARC1; p=none; rua=mailto:your-report-address`. This changes nothing about delivery and starts the reports flowing.
  3. 3Use a reporting address that can handle the volume. Aggregate reports are compressed XML, one per receiver per day. Sign in to MailVakt and add your domain to get a reporting address and a readable weekly summary instead of a mailbox full of gzip.
  4. 4Read a week of reports. The reports list every IP sending as your domain and whether SPF and DKIM aligned. Fix the legitimate senders that are not aligning before you touch the policy.
  5. 5Move to enforcement in stages. `p=quarantine; pct=25`, then `p=quarantine`, then `p=reject`. Set `sp=reject` once your subdomains are accounted for, and keep `rua` in place permanently.

Questions

What is the simplest valid DMARC record?
`v=DMARC1; p=none; rua=mailto:reports@example.com` as a TXT record at `_dmarc`. It is safe to publish today and it is what gives you the data for every later decision.
Do I need DMARC if I do not send email?
Yes, and it matters more. A parked domain should publish `v=DMARC1; p=reject; sp=reject;` along with an SPF record of `v=spf1 -all` and a null MX, so nobody can send as it.
Does every subdomain need its own record?
No. Subdomains fall back to the organisational domain's policy, or to `sp=` if you set one. Publish a subdomain record only when it needs a different policy or a different reporting address.
Will publishing DMARC break my email?
`p=none` does not change delivery; it only requests reports. Breakage risk comes later, when you move to quarantine or reject before your senders are aligned.

Fix this from ChatGPT or Claude

MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:

“example.com has no DMARC record. Check the domain and give me a safe starting DMARC record with reporting turned on.”
  • Claude: Settings → Connectors → Add custom connector, then paste https://mcp.mailvakt.com/mcp.
  • Cursor and other MCP clients: add the same address as an MCP server. Setup details.

Checks are free and need no account. Sign in only to collect DMARC reports for a domain.