Free Tool

DMARC Subdomain Policy Checker

Check DMARC policy coverage across your domain's subdomains.

DMARC Subdomain Policy Checker

or

Frequently Asked Questions

Common questions about DMARC subdomain policies

What is a DMARC subdomain policy?

A DMARC subdomain policy (sp=) specifies how receivers should handle messages from your subdomains. If not set, subdomains inherit the main domain's policy (p=). You can set stricter policies for subdomains.

Do subdomains need their own DMARC records?

No, by default subdomains inherit the main domain's policy. You can publish specific records for individual subdomains at _dmarc.subdomain.example.com if needed, or use sp= tag for all subdomains.

Why are subdomains vulnerable without DMARC?

Attackers often use subdomains like 'secure.yourcompany.com' for phishing because users trust any @yourcompany.com address. Without sp=reject, subdomains may only have weak p=none protection.

Help & Resources

Best Practices for Subdomain DMARC

  • Set explicit DMARC policies for all subdomains, especially those used for mail.
  • Use p=reject for sensitive or unused subdomains.
  • Inherited policies are better than none, but explicit is best.
  • Monitor reports to detect abuse of unprotected subdomains.
Why Coverage Matters

Attackers often exploit unprotected subdomains. Full coverage helps prevent spoofing and phishing.

Learn More

Need more help? Check out our documentation or contact support.