RFC 7489 DMARC Policy Validator
Instant RFC 7489 DMARC policy inspector. Evaluates policy enforcement levels (`p=none`, `quarantine`, `reject`), organizational domain tree-walking fallbacks, SPF/DKIM alignment rules, and RFC 7489 § 7.1 external destination authorization.
INITIALIZING DMARC ENGINE...
RFC 7489 Architecture & Delivery Standards
// REFERENCE SPECOrganizational Domain Fallback
Per RFC 7489 Section 6.6.3, if a deep subdomain like app.staging.example.com has no direct DMARC record, receivers perform exactly one fallback query at the Organizational Domain (example.com) determined by the Public Suffix List (PSL).
The Danger of p=none
Over 60% of published DMARC records use p=none. While useful for initial telemetry, p=none instructs mail receivers to deliver fraudulent emails directly to user inboxes, leaving domain reputation exposed to impersonation.
RFC 7489 § 7.1 Verification
When sending reports to external endpoints (e.g. dmarc@thirdparty.com), the receiving domain must publish an authorization record at domain._report._dmarc.thirdparty.com. Without this, receivers will drop telemetry reports.