About this tool

DMARC is read alongside SPF because it is the policy that ties the visible From address to authentication results; checking it is a standard step when investigating whether a domain could be, or already is, spoofed in phishing or business email compromise.

Example inputs: example.comdigitpol.coma-supplier-domain.com

What the result shows

Policy (p=)
The requested handling for failing mail: none for monitoring only, quarantine, or reject.
Subdomain policy (sp=)
An optional separate policy applied to subdomains of the domain.
Reporting addresses (rua/ruf)
Destinations the domain owner wants aggregate or forensic DMARC reports sent to; these are not necessarily the domain's operator.
Record presence
Whether any DMARC record exists at all, since no record means no stated policy.

Investigation use cases

  • Checking whether a domain used in a suspected phishing email enforces a reject or quarantine policy
  • Assessing a company's own email authentication posture before a security audit
  • Comparing DMARC adoption between a genuine brand domain and an impersonator
  • Supporting a business email compromise investigation by documenting the sender domain's policy

Limitations

This tool reports the published policy text only, it does not evaluate a specific message against DMARC, and a strict policy on a domain does not prevent a lookalike domain from being used instead of the real one.

Frequently asked questions

Does p=none mean the domain is unprotected?

It means DMARC is in monitoring mode only, failing messages are not blocked or quarantined based on this record, though reports may still be collected.

Can DMARC stop a lookalike domain from sending phishing email?

No, DMARC only governs mail claiming to be from the exact domain it is published on, not similarly named domains.

Why is there no DMARC record at all for some domains?

Many domains, especially smaller or older ones, have simply never configured DMARC; this is common and not itself a sign of compromise.

Is there a free tier?

The check is free within daily limits; a sealed report is a paid or account feature.

Need evidence you can keep?

Every lookup produces a full public-source report sealed with a SHA-256 digest. Accounts keep a saved history and can download the DIGITPOL PDF report.