DMARC Validator API

GET

Know if any domain has a valid DMARC record and policy.

DMARC Validator checks the Domain-based Message Authentication, Reporting and Conformance (DMARC) record for a domain to ensure it is correctly configured.

Try it — live request, no key required

Request
GETapi.apiverve.com/v1/dmarcvalidator?domain=paypal.com
Query parameters
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "host": "paypal.com",
    "dmarcHost": "_dmarc.paypal.com",
    "hasDmarc": true,
    "dmarc_record": "v=DMARC1; p=reject; rua=mailto:[email protected],mailto:[email protected]; ruf=mailto:[email protected],mailto:[email protected]",
    "rua": {
      "email": "[email protected],[email protected]",
      "domain": "rua.agari.com",
      "valid": true
    },
    "ruf": {
      "email": "[email protected],[email protected]",
      "domain": "ruf.agari.com",
      "valid": true
    },
    "v": "DMARC1",
    "p": "reject",
    "sp": null,
    "pct": null,
    "adkim": null,
    "aspf": null,
    "fo": null,
    "rf": null,
    "ri": null,
    "valid": true,
    "issues": [],
    "isEnforced": true,
    "riskScore": 5,
    "riskLevel": "low"
  }
}

About the DMARC Validator API

A DMARC record lookup API. This tool queries DNS records to inspect and validate the DMARC record associated with a domain. It analyzes policy strength, formatting and alignment modes, derives whether the domain actively enforces DMARC and a composite email-spoofing risk score, and provides guidance for better email deliverability and protection against spoofing.

What people use it for

Vendor Security Audits
Audit partner domains during vendor reviews by inspecting their published DMARC policy and flagging entries set to none instead of reject.
Outbound Campaign Verification
Before sending mass marketing broadcasts, deliverability platforms verify sender domains to confirm that DMARC records exist and specify strict alignment modes.
Inbound Mail Protection
To stop spoofed sender addresses, secure email gateways evaluate incoming message domains against live DMARC policies and quarantine suspicious traffic.
Domain Portfolio Health
DNS administrators track customer domains across registrars to detect misconfigured report addresses, missing subdomain policies, and unaddressed syntax issues.

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

How it compares

Side by side with the tools people weigh DMARC Validator against — what each one is better at, in plain terms.

Other ways to use DMARC Validator

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the DMARC Validator API.

Read the docs →
How far does the Starter plan go for domain checks?
Starter covers 20,000 domain validations each month. That works out to about $0.0015 per call, or $1.50 per 1,000 checks. If you want to evaluate responses before committing, the Free plan includes 20 calls per month.
Are the spoofing risk score and enforcement status included on the Free plan?
No, risk scores, risk levels, and the enforcement flag are premium fields reserved for paid plans. The Free plan returns basic record validation and alignment tags, while any paid plan unlocks full risk scoring, enforcement checks, and reporting email validation.
Does this check live DNS records or cached data?
DMARC Validator queries DNS records in real time on every call. It looks up the live TXT record published for the domain, ensuring you inspect current policies, report destinations, and alignment modes as soon as DNS changes propagate.
What happens if a domain has no DMARC record published?
When a domain lacks a DMARC entry, the response sets hasDmarc to false and marks valid as false. Specific problems, such as a missing policy tag or absent record, are returned in the issues array so your code can handle unconfigured domains cleanly.
Can I use these validation results inside my commercial SaaS platform?
Yes, commercial use is allowed on all paid plans. You can embed the validation and spoofing risk metrics into your own email deliverability monitors, onboarding workflows, or security dashboards, as long as you do not resell or redistribute the raw API responses directly.

Ready to build with DMARC Validator? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs