Skip to main content
lowSecurity & Infrastructure

DMARC Record

DMARC is the policy record that makes SPF and DKIM enforceable — and major inbox providers now require it from bulk senders. SaaSalyst checks DNS at _dmarc.yourdomain for a published DMARC policy.

What SaaSalyst Checks

SaaSalyst queries the _dmarc TXT record at your registrable domain for a v=DMARC1 policy. Present passes; absent warns. Warn-only at low severity — the scanner cannot know whether the domain sends mail.

Why This Matters

Without DMARC, receivers have no instruction for mail that fails SPF/DKIM checks — so spoofed mail from your domain gets delivered anyway. Gmail and Yahoo made DMARC mandatory for bulk senders in 2024; a SaaS sending onboarding and billing email without it is accumulating deliverability risk and leaving its brand open to phishing reuse.

How to Fix It

  1. Publish a TXT record at _dmarc.yourdomain.com: v=DMARC1; p=none; rua=mailto:you@yourdomain.com to start monitoring.
  2. Review the aggregate reports, then tighten the policy to p=quarantine and eventually p=reject.
  3. Ensure SPF and DKIM are aligned first — DMARC enforcement without them will quarantine your own mail.

Frequently Asked Questions

What DMARC policy should a small SaaS start with?

p=none with a reporting address. SaaSalyst flags absence rather than policy strength: p=none costs nothing, breaks nothing, and gives you the failure reports needed to safely reach p=reject later.

Why does SaaSalyst warn instead of fail on a missing DMARC record?

Because a scanner cannot verify that your domain sends mail at all, and a check that cannot be sure should not penalize. SaaSalyst carries SPF and DMARC at low, warn-only weight until fail states can be grounded in observed sending.

Check Your SaaS Now | Free

SaaSalyst scans your website in 30 seconds and checks for DMARC Record along with 118+ other business readiness signals.

Scan Your App

Related Checks SaaSalyst Runs