ReaperCloud

Record Generator

Tell receivers what to do with mail that fails, and where to send the reports.

Start at none. Move up once your reports show only senders you recognise.
Where the daily XML goes. The most useful tag in the record.
Percent of mail. Leave blank for all of it.
Less common tags

How to use this

It will argue with you

Asking for p=reject with no reporting address gets you an error, not a record. The generator that quietly emits whatever you asked for is how domains break their own mail.

Order matters more than syntax

DMARC at none with reporting, then read reports for a few weeks, then quarantine, then reject. Every step you skip, you find out about from a customer.

The records nobody mentions

External reporting addresses need an authorisation record in the other domain. MTA-STS needs a hostname and a hosted file. We list those alongside the main record rather than leaving you to find out later.

Then check it

A record that is right in the form and wrong in DNS is common — providers mangle quoting, split strings, or append the zone name. Verify with the lookup tools after publishing.