dmarc
No DMARC record found: what it means and the 10-minute fix
A checker says your domain has no DMARC record. Here is what that means, why it happens even after you add one, and the exact starter record to publish.
DMARC Done team · 5 October 2026 · 6 min read
“No DMARC record found” is one of the most common results a domain checker returns. It is also one of the easiest problems to fix. This post explains what the message means, why it sometimes appears even after you have added a record, and gives you a safe starter record you can publish in about ten minutes.
What the message means
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is a short text record in your domain’s DNS (the Domain Name System, the internet’s address book) that tells receiving mail servers two things:
- What to do with email that claims to come from your domain but fails authentication.
- Where to send reports about the mail they see using your domain.
The record always lives at one specific address: _dmarc.yourdomain.com, as a TXT record that starts with v=DMARC1. The DMARC standard sets this location. That standard is now RFC 9989, published in May 2026, which replaced the original RFC 7489.
When a checker says “no DMARC record found”, it means it asked DNS for a TXT record at _dmarc.yourdomain.com and got nothing back that starts with v=DMARC1.
Why it matters
Without a DMARC record, receiving servers have no instruction from you. Anyone can put your domain in the From line of an email, and nothing you published tells Gmail or Outlook to treat that mail with suspicion.
You also get no reports. That means you cannot see which services send mail as your domain, which of them pass authentication, and whether someone else is impersonating you.
Big mailbox providers have also started to ask for DMARC. Since February 2024, Google’s sender guidelines require anyone sending more than 5,000 messages a day to Gmail accounts to publish a DMARC record (a policy of none is enough). Yahoo set the same rule for bulk senders at the same time, and Microsoft requires it from domains that send 5,000 or more messages a day to Outlook.com and its other consumer services. A small business is usually below those thresholds, but the direction is clear: the big inboxes expect DMARC.
Microsoft is open about how it handles a missing record. When there is no DMARC record for the From domain, Microsoft 365 shows dmarc=bestguesspass in the message headers, which means it guessed. Its own troubleshooting table gives the fix: “Publish an explicit DMARC record.”
Why it says “not found” even after you added a record
If you are sure you added a record and the checker still finds nothing, one of these is usually the cause:
- The host name was doubled. Many DNS panels add your domain automatically. If you typed
_dmarc.yourdomain.cominto such a panel, the record may now live at_dmarc.yourdomain.com.yourdomain.com. In most panels you type only_dmarc. - You edited DNS in the wrong place. Your domain may be registered at one company while its DNS is hosted at another (for example, registered at GoDaddy but using Cloudflare name servers). Only the DNS host’s records count.
- The record type is wrong. DMARC must be a TXT record, not a CNAME or a “SPF” type record.
- The value does not start with
v=DMARC1. A missingv=, a lowercasedmarc1or extra text in front of it makes receivers ignore the record. - There are two DMARC records. If there are two TXT records at
_dmarcthat both start withv=DMARC1, the original DMARC specification (RFC 7489) tells receivers to stop and apply no DMARC at all. Keep exactly one. - It has not propagated yet. DNS changes are often visible within minutes, but caches can hold the old answer for the record’s TTL (time to live). If the TTL was long, give it an hour or two.
The 10-minute fix
Step 1: Create a mailbox for reports (2 minutes)
Pick an address that will receive DMARC reports, such as dmarc-reports@yourdomain.com. Make it a real mailbox, alias or group so the reports are not bounced. Microsoft recommends a dedicated mailbox or group for this, not a person’s main inbox, because reports arrive as compressed XML attachments every day.
Step 2: Open your DNS settings (3 minutes)
Log in to the company that hosts your DNS. If you are not sure who that is, run the free checker at /check?d=yourdomain.com: it shows your DNS host and links to the matching guide.
Step 3: Add one TXT record (3 minutes)
Add a new record with these values:
Type: TXT
Host: _dmarc
Value: v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com; fo=1
TTL: 1 hour (3600), or your panel's default
Replace yourdomain.com with your own domain in the rua address. If your DNS panel asks for the full name instead of just _dmarc, enter _dmarc.yourdomain.com. Our provider guides show the exact convention for each panel.
Step 4: Check it (2 minutes)
Wait a few minutes, then run the checker again. You should see a DMARC record with policy none.
What each part of the starter record does
v=DMARC1identifies the record as DMARC. It must come first.p=noneis the policy. It tells receivers to take no special action on mail that fails. Nothing about your delivery changes, which is why this is the safe first step.rua=mailto:...is where aggregate reports go. These are daily summaries from receivers listing which servers sent mail as your domain, how many messages, and whether they passed.fo=1asks for a failure report whenever SPF or DKIM fails, rather than only when both fail. It only has an effect if you also add aruf=address for failure reports, and many large providers do not send failure reports at all (Microsoft 365, for example, does not). It is harmless to include and saves an edit later.
You will notice the record has no pct tag. Under RFC 7489 it defaulted to 100 percent anyway, and RFC 9989 has dropped it from the standard, so there is no reason to add it.
Plain-English takeaway: “No DMARC record found” means nothing is published at
_dmarc.yourdomain.com. Add one TXT record withp=noneand a reporting address. It changes nothing about how your mail is delivered, and it starts the reports you need for the next step.
If your reports go to another domain
If the rua address is on a different domain from the one you are protecting (for example, a reporting service), the receiving domain has to publish a small authorization record, or receivers will not send the reports. This check was defined in RFC 7489, section 7.1. Reporting services handle this on their side, so you normally do not need to do anything. If you point reports at your own domain, it does not apply.
Before and after you publish
DMARC builds on two older checks:
- SPF (Sender Policy Framework) lists the servers allowed to send mail for your domain.
- DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message.
A message passes DMARC when at least one of them passes and matches the domain in the From address. You can publish the DMARC record before SPF and DKIM are perfect, because p=none does not block anything. But you should fix SPF and DKIM before you move to a stricter policy. The free checker shows the status of all three.
What comes next
A p=none record is a starting point, not protection. Scanners will now stop saying “no DMARC record found” and start saying “DMARC policy not enabled” instead. Our post on what “DMARC policy not enabled” means explains why.
The path from here:
- Read the aggregate reports for two to four weeks and list every service that sends mail as you.
- Make each legitimate service pass SPF or DKIM with your domain.
- Move to
p=quarantine, thenp=reject. Our post on quarantine vs reject covers the safe order.
If you would rather not read XML reports and chase down every sender yourself, we do it for you. See pricing: one fee per domain, and a full refund if your domain is not at p=reject within 60 days.
Sources
- RFC 9989, Domain-Based Message Authentication, Reporting, and Conformance (DMARC): https://www.rfc-editor.org/rfc/rfc9989.html
- RFC 7489, DMARC (obsoleted by RFC 9989), sections 6.3, 6.6.3 and 7.1: https://www.rfc-editor.org/rfc/rfc7489.html
- IANA DMARC Tag Registry (pct marked historic): https://www.iana.org/assignments/dmarc-parameters/dmarc-parameters.xhtml
- Microsoft Learn, Set up DMARC to validate email in Microsoft 365: https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dmarc-configure
- Google, Email sender guidelines: https://support.google.com/mail/answer/81126
- Yahoo Sender Hub, Sender best practices: https://senders.yahooinc.com/best-practices/
- Microsoft Support, Fix NDR error 550 5.7.515 in Outlook.com (high-volume sender requirements): https://support.microsoft.com/en-us/outlook/fix-ndr-error-550-5-7-515-in-outlook-com