DMARC record checker
See whether a domain tells receivers what to do with mail that fakes its name — and how strictly.
- Policy, subdomain policy and percentage
- Alignment and reporting addresses
- Findings in plain English
Give it something to look up — Glee will do the digging.
How the dmarc checker works
DMARC is the record that ties SPF and DKIM together and gives a domain owner a say in what happens to mail that fails them. Without it, anyone can send mail that appears to come from the domain and receivers decide on their own. With p=reject, receivers are asked to refuse such mail outright.
This checker reads the record at _dmarc.<domain>, and reports the policy, the policy for subdomains, the percentage of mail it applies to, alignment modes and where aggregate and failure reports are sent. It flags the common gaps: a policy of none left in place for months, a percentage below 100, and missing or malformed tags.
For a supplier or partner, a reject policy is a sign the domain is actively managed; for your own domain, the findings are a to-do list.
What each field means
- Policy
- none (monitor only), quarantine (spam folder) or reject.
- Alignment
- Whether the visible From domain must match exactly (strict) or by organisation (relaxed).
Where this check stops
- Report the policy and the evidence; a policy does not prove deliverability or prevent every impersonation (look-alike domains are not covered).
The same check, through the API
Same calculation, same answer, with a key. 3 credits per check ($0.30 per 1,000). A free account includes 1,000 credits a month.
GET /v1/email-auth/acme.com Host: gleanzy.com Authorization: Bearer $GLEANZY_KEY
Frequently asked
Is p=none useless?
It is a monitoring stage: reports flow, nothing is blocked. It is meant to be temporary.