Support
Loading...

Check Your DMARC Record in NicNames DNS

8 October 2026

DMARC tells receiving mail systems how to handle messages that fail aligned SPF or DKIM checks for your domain. Here is how to find the published DMARC TXT record, read its policy, and spot problems before you change any email settings.

1. Check where your DNS is hosted

Sign in to NicNames and open Domains → ClassicDNS. Select the domain’s Settings and review Name-Servers. If the domain uses Free Name-Servers, open DNS Records → Manage. If it uses Custom Name-Servers, review the records at the provider named there; a record saved in an inactive DNS zone will not appear publicly.

2. Find the DMARC TXT record

The NicNames record list shows Name, TTL, Type and Data. Look for a TXT record at _dmarc for your sending domain. For example.com, the full public name is _dmarc.example.com. The text should start with v=DMARC1 and include a policy such as p=none, p=quarantine or p=reject. Do not confuse it with an SPF TXT record at the domain or a DKIM selector record under _domainkey.

3. Read the policy before changing it

p=none asks receivers for no DMARC-specific enforcement and is commonly used while monitoring. p=quarantine asks receivers to treat failing mail as suspicious; p=reject asks them to reject it. The receiving system makes the final handling decision. An optional rua=mailto: address receives aggregate reports if receivers send them. Check that the address is intended to receive and process those reports.

A DMARC pass requires an SPF or DKIM pass aligned with the visible From domain. Review every service that sends as your domain before tightening a policy, including newsletters and website forms. If you use Google Workspace, our SPF checklist helps you review one part of that setup. For Microsoft 365, see the separate DKIM selector guide. Use the values and guidance for your actual mail provider.

4. Verify the public answer

Look up the TXT answer for the full _dmarc name through a public DNS lookup and compare it with the record at the authoritative provider. If it is missing or differs, first check the active nameservers and allow for the existing TTL; our DNS troubleshooting guide explains that comparison. More than one DMARC record at the same name can also cause problems. Send a test message from each legitimate sending service and inspect its authentication results, then review aggregate reports over time rather than judging a policy from one test.

If the record is missing or a stricter policy could affect legitimate mail, map your senders and consult your email provider’s current rollout guidance before saving a change. NicNames Support can help you find the active DNS zone.

Share this article:
Ask Jexi