DMARC is a short DNS record that tells mail providers such as Gmail and Outlook what to do with a message that claims to come from your domain but fails the SPF and DKIM checks. It also asks them to send you reports, so you can see who is sending mail in your name. This guide explains how to write the record, where to add it for each Domain India control panel, and how to move safely from monitoring to blocking.
A DMARC record is a TXT record named _dmarc with a value such as v=DMARC1; p=none; rua=mailto:[email protected]. Add it wherever your domain's DNS is actually managed: your hosting control panel if the domain uses our hosting nameservers, otherwise Cloudflare or your DNS provider. A domain may have only one DMARC record, and most domains on our cPanel servers already have a p=none record, so edit that one rather than adding a second. Start with p=none, read the reports for a few weeks, then tighten to quarantine and finally reject.
1. What DMARC does
DMARC sits on top of two older checks:
- SPF lists the servers allowed to send mail for your domain.
- DKIM signs each message with a key published in your DNS.
DMARC adds two things. First, alignment: a message passes DMARC only if SPF or DKIM passes for the same domain that appears in the visible From address. Second, a policy: what the receiving server should do when a message fails, plus an address for reports.
Without DMARC, anyone can put your address in the From line and receivers have no instruction from you. Large mailbox providers now expect bulk senders to publish SPF, DKIM and DMARC. Note that DMARC controls how other providers treat mail claiming to be from you; it does not filter the mail you receive.
2. Before you start: check SPF, DKIM and where your DNS lives
DMARC only works when your real mail already passes SPF or DKIM. Check both first:
- Send a message from your domain's mailbox to a Gmail address.
- In Gmail, open the message menu and choose Show original.
- Look for
SPF: PASSandDKIM: PASSwith your domain. ADMARC:line appears there too once a record exists.
Then find out where your domain's DNS is managed, because the record must go there. If the domain uses our hosting nameservers, use your control panel's DNS editor; if it points to Cloudflare, your registrar or another DNS host, use that provider's dashboard. Records saved in a DNS editor that the internet does not query have no effect. If you are not sure, see How do I change my nameservers.
3. Check whether you already have a DMARC record
A domain must have exactly one DMARC record. Two records make DMARC invalid, and receivers then ignore both.
On 23 September 2026 we counted the zones on our shared servers. On our cPanel servers, 1,377 of 1,819 zones already had a DMARC record, almost all of them v=DMARC1; p=none; with or without a report address. On our DirectAdmin server only 61 of 2,553 zones had one. So on cPanel you will usually edit an existing record, and on DirectAdmin you will usually add one.
Look it up from any computer:
dig +short TXT _dmarc.yourdomain.comOn Windows, use nslookup -type=TXT _dmarc.yourdomain.com. If the answer starts with v=DMARC1, a record exists: change it rather than create another.
4. Build your DMARC record
A DMARC record is a list of tag=value pairs separated by semicolons. Only v and p are required.
| Tag | Example | What it does |
|---|---|---|
| v | v=DMARC1 | Version. Must come first |
| p | p=none | Policy for your domain: none, quarantine or reject |
| rua | rua=mailto:[email protected] | Where daily aggregate reports are sent |
| sp | sp=reject | Policy for subdomains, if different from p |
| pct | pct=50 | Apply the policy to only this percentage of failing mail |
| adkim | adkim=r | DKIM alignment: r (relaxed, default) or s (strict) |
| aspf | aspf=r | SPF alignment: r (relaxed, default) or s (strict) |
| ruf | ruf=mailto:[email protected] | Per-message failure reports; most large providers do not send them |
The three policies:
p=nonemeans monitor only. Nothing changes for your mail, but you receive reports.p=quarantineasks receivers to put failing mail in spam.p=rejectasks receivers to refuse failing mail outright.
A good first record is:
v=DMARC1; p=none; rua=mailto:[email protected]Use a mailbox you read, or a DMARC report service. A report address on a different domain needs an authorisation record on that domain, or receivers will not send the reports; report services give you the exact record.
5. Add the record in your control panel
The record is always the same three things: type TXT, name _dmarc, and your value. Only the place you type it changes.
cPanel
- Open the Zone Editor.Log in to cPanel (see How to log in to cPanel) and go to Domains › Zone Editor.
- Click Managenext to your domain and filter by TXT.
- Edit the existing record if there is one.Look for a record named
_dmarc.yourdomain.com.and click Edit. Replace the value with your new one and save. - Otherwise add one.Choose Add Record › TXT. Name:
_dmarc.yourdomain.com.(typing_dmarcis usually completed for you). Value: your DMARC record. Keep the default TTL, then save.
The full walkthrough of the Zone Editor is in How to make DNS changes in cPanel. cPanel's Email › Email Deliverability page checks your SPF and DKIM; use it to fix those before you tighten DMARC.

DirectAdmin
Open DirectAdmin's DNS Management page for the domain, add a TXT record with the name _dmarc and your value, and save. DirectAdmin signs mail with the DKIM selector x; if DKIM is not working yet, follow How to check and manage DKIM in DirectAdmin first.

Webuzo and Plesk (Windows)
Both panels have a DNS editor for the domain. In Webuzo it is Domain › DNS Zone Settings, and new Webuzo zones already contain a _dmarc TXT record (v=DMARC1; p=none;): edit that record with your value rather than adding a second one, because two DMARC records are invalid. In Plesk, add a TXT record named _dmarc with your value. If you cannot find the DNS page in Plesk, ask support and we will point you to it. For Windows hosting in general, see the Plesk Windows hosting guide.

Cloudflare or another DNS provider
Add a TXT record with the name _dmarc (most providers add your domain automatically) and paste the value. On Cloudflare, TXT records are never proxied, so there is nothing else to set.
After saving, repeat the dig lookup from section 3: you should see exactly one line beginning v=DMARC1 (other networks may cache the old answer for a few hours). Then send a test message to Gmail; DMARC: 'PASS' under Show original confirms your mail is aligned.
6. Read the reports, then tighten the policy
Aggregate reports arrive as compressed XML, usually daily from each large provider, listing every server that sent mail as your domain and whether it passed. A DMARC report service (many have a free tier) makes them readable. Use them to find every legitimate sender (hosting mail server, newsletter tool, billing or CRM system, website form) and make each pass SPF or DKIM for your domain. Then tighten step by step:
- Monitor.Keep
p=nonefor two to four weeks while you fix any legitimate sender that fails. - Quarantine a share.Move to
p=quarantine; pct=25, then raisepcttowards 100 as the reports stay clean. - Reject.Move to
p=rejectonce genuine mail passes consistently. Spoofed mail in your name is then refused.
If one of your real senders is not aligned, p=reject makes its mail bounce, and you may only notice when customers report missing invoices or password emails.
7. When genuine mail fails DMARC
| What you see | Likely cause | Fix |
|---|---|---|
| DMARC fail for a newsletter or CRM tool | That service sends as your domain but is not in SPF and does not sign with your DKIM | Add its SPF include and publish the DKIM record it gives you |
| DMARC fail on forwarded mail | Forwarding breaks SPF for the next hop | Rely on DKIM, which usually survives forwarding |
| Website form mail fails | The form sends From a Gmail or other outside address | Send From an address on your own domain |
| Record ignored | Two DMARC records, or a typo such as a missing semicolon | Keep one record and check the syntax |
On our cPanel servers, SRS (the rewrite that keeps SPF working for forwarded mail) is off, so mail forwarded from a cPanel mailbox to an outside address depends on DKIM to pass DMARC. For PHP contact forms, see How to use PHPMailer for contact forms, which shows how to send from your own domain on our servers.
8. DMARC on Domain India hosting and email
Every Domain India shared hosting plan lets you manage DNS records for domains that use our hosting nameservers, so you can publish SPF, DKIM and DMARC yourself. On cPanel, DKIM uses the selector default and most zones already carry a p=none DMARC record; on DirectAdmin, DKIM uses the selector x and you normally add the DMARC record yourself.
Shared hosting also has sending limits: 200 messages per hour per account on cPanel and 1,000 per day (200 per mailbox by default) on DirectAdmin. For newsletters, use a dedicated sending service and authorise it in SPF and DKIM before you tighten DMARC.
Domain India Business Email signs every message with DKIM and provides SPF and DMARC records for your domain.
- Priced per mailbox - start with one
- Email at your own domain ([email protected])
- Add and remove mailboxes yourself
- Webmail with calendar, contacts and tasks
The price on the card is a live Domain India list price and excludes 18% GST. For the wider picture of SPF, DKIM, DMARC, BIMI and MTA-STS, see Email deliverability: SPF, DKIM, DMARC and BIMI.
Frequently asked questions
What is a DMARC record?
A DMARC record is a TXT record at _dmarc.yourdomain.com that tells receiving mail servers what to do with messages that fail SPF and DKIM alignment for your domain (none, quarantine or reject) and where to send reports about them.
Can my domain have two DMARC records?
No. A domain must have exactly one TXT record at _dmarc. If there are two, receivers treat DMARC as invalid. Edit the existing record instead of adding another.
Does my Domain India cPanel domain already have DMARC?
Usually yes. On 23 September 2026, 1,377 of 1,819 zones on our cPanel servers already had a DMARC record, almost all with p=none. Check with dig +short TXT _dmarc.yourdomain.com and edit the existing record in the Zone Editor.
When should I move to p=reject?
Only after the reports show all of your genuine mail passing DMARC for a few weeks. Move from none to quarantine first, optionally with pct to apply it to part of your mail, and then to reject.
Why does forwarded mail fail DMARC?
Forwarding sends the message from a different server, so SPF no longer matches your domain. DKIM usually survives forwarding, which is why a working DKIM signature matters for DMARC.
Ready to publish your record? Check where your domain's DNS is managed, add or edit the _dmarc TXT record, and test it with Gmail's Show original. If a record will not save or your mail starts failing, open a support ticket with your domain name: support is on 24/7 live chat, and tickets get a first response within 15 minutes.
Tell us your domain and where its DNS is managed, and we will check your SPF, DKIM and DMARC records with you.
Open a support ticket