Enter your domain and abr.cloud reads its DMARC policy — the rule that tells the world what to do with mail that fails your checks — and explains, in plain language, whether you're actually protected and what to change.
One quick verification, no account. We store nothing unless you start monitoring.
DMARC ties SPF and DKIM together and tells receiving servers what to do when a message fails: nothing (p=none), send it to spam (p=quarantine), or reject it outright (p=reject). It also sends you reports of who is sending mail as your domain. Without DMARC at enforcement, anyone can spoof your exact address.
p=quarantine or p=reject — p=none only monitors, it protects nothing.rua=) so you can see who sends as you before tightening._dmarc.yourdomain.p=none with rua= reporting and watch for a couple of weeks.p=quarantine, then p=reject once reports are clean.Yes — free with a quick CAPTCHA, no account. It reads only public DNS.
No. p=none only collects reports; it tells receivers to do nothing, so spoofed mail still gets delivered. Move to quarantine or reject once your legitimate senders pass.
A working SPF record and DKIM signing, both aligned with your From domain — check those first, then tighten DMARC.
abr.cloud puts 80+ network & security tools behind one fast interface — with AI analysis and always-on monitoring.
open abr.cloud →