Dmarc Overview

Managed record tools

Managed records let DMARC+ host the content of your DMARC, SPF and BIMI records. You publish one small pointer in your DNS, and later changes are made from DMARC+ without touching your DNS host again.

When to use managed records

Use managed records when Use plain records when
You change policies often, for example during rollout You want full control in your own DNS
Many domains share one setup Your DNS host cannot create the required record type
The DNS team is slow to respond Policy or compliance requires all records to live in your zone

Where to find them

Open DMARC+ > Manage, then choose Managed DMARC, Managed SPF or Managed BIMI.

How they work

  1. Pick a domain and build the record with the generator.
  2. DMARC+ stores the record under a name it controls and returns that name.
  3. You create a CNAME in your DNS that points to it.
  4. When you change the record in DMARC+, DNS resolvers see the new value once caches expire.

Important: a CNAME cannot exist alongside other records with the same name. Before publishing a managed DMARC record, delete any existing TXT record at _dmarc.<your domain>. The same applies to the SPF and BIMI names if you replace them with a pointer.

Note: the Managed SPF screen shows a table with Host, Type and Value. Follow the instructions that the screen shows for your domain, since the record type your DNS host needs is decided by the row shown there.

Managed DMARC generator

Setting Options Notes
Policy None, Quarantine, Reject Start at None
Subdomain Policy Same as domain, None, Quarantine, Reject Use Same until subdomains are clean
SPF alignment Relaxed (default), Strict See What is DMARC?
DKIM alignment Relaxed (default), Strict
Percentage 1 to 100 Phase in enforcement
Forensic options 0, 1, d, s Only matters if ruf is set
Aggregate and forensic addresses Email addresses Your DMARC+ addresses must stay in the list

The tool shows the finished record, for example v=DMARC1; p=none; rua=mailto:...; pct=100; adkim=r; aspf=r.

Tip: check that the generated record contains a rua address that goes to DMARC+. If you remove it, no reports will reach the platform.

Managed SPF generator

Inputs: A records, MX records, IP addresses, third-party services, and a failure type.

Failure type Effect When
Fail (-all) Reject unlisted senders After all senders are known
Soft Fail (~all) Mark unlisted senders as suspicious During discovery
Neutral (?all) No statement Rarely useful

The result is shown as Generated SPF Record. Select Publish Record to store it.

Tip: use the generator to keep the record under 10 DNS lookups. See What is SPF?.

Managed BIMI generator

Inputs: trust authorities, logo URL and location. The record is published under the default._bimi name. See What is BIMI?.

After publishing

  1. Wait for DNS caches to expire.
  2. Open the matching tool under Tools and check the record resolves.
  3. Refresh the domain on the Domains page. The status should turn Valid.

Remove a managed record

Replace the CNAME in your DNS with a plain record of your own, or delete it. Plan this carefully: without a record at _dmarc, you stop receiving reports.