~/tools / dns-explainer
DNS Record Explainer
Paste any DNS record and get a plain-English breakdown - every tag explained, risky settings flagged, related tools suggested. No domain needed.
[ OK ]
Detected: DMARC
input
v=DMARC1; p=none; rua=mailto:[email protected]
[ explanation · ai ]
[ breakdown ]
v=DMARC1
Version tag. Always "DMARC1" for now. Mandatory, must come first.
p=none
Policy. Tells receivers what to do with mail that fails DMARC alignment. "none" means monitor only—don't reject or quarantine, just report. Other options: "quarantine" (spam folder) or "reject" (hard fail). You're currently in observation mode.
rua=mailto:[email protected]
Reporting URI for aggregate reports. Receivers send you weekly XML summaries showing pass/fail counts by sender IP and domain. The mailbox must exist and ideally should filter/archive these automatically since volume adds up. This is your only visibility into DMARC results across your mail ecosystem.
[ flags ]
• No RUE (ruf=) tag present. You won't get forensic reports on individual message failures—only aggregates. If debugging specific rejection issues matters, add ruf=mailto:[email protected].
• p=none combined with no DKIM or SPF mention means you haven't enforced alignment yet. This is fine for testing but leaves you vulnerable to spoofing; verify your SPF and DKIM records are correct before tightening to "quarantine" or "reject".
• No "fo=" (failure options) tag. Defaults to "0" (report on full alignment failure only). If you need reports on partial failures, add fo=1.
• No "pct=" tag. Defaults to 100%, so policy applies to all mail. Consider pct=10 during rollout to sample failures before full enforcement.
[ context ]
DMARC requires a TXT record at _dmarc.yourdomain.com (not the root). It sits on top of SPF and DKIM—those must authenticate your legitimate mail first or DMARC will always fail. Without this record, receivers ignore DMARC and you get no reports. With p=none, you're gathering data risk-free; move to stricter policies only after confirming legitimate mail passes alignment tests for weeks.
[ related ]
// AI explainer uses Claude Haiku 4.5. Same record pasted twice = served from 7-day cache. Never leaves our servers - no analytics/telemetry on paste content.