dmarc PROTOCOLHost: Google Cloud DNSStandard: RFC 7489
How to Configure Domain-based Message Authentication, Reporting, and Conformance (DMARC) on Google Cloud DNS
Enforces receiver policy (none, quarantine, reject) when SPF and/or DKIM alignment fails, and generates forensic aggregate reports. Follow this verified implementation guide to deploy standard compliant DMARC DNS records in Google Cloud DNS.
Default DMARC Record Syntax
// Authoritative RFC Example
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com; pct=100; aspf=r; adkim=rConfiguration Steps in Google Cloud DNS
- 1Open the Google Cloud Console and navigate to Network Services -> Cloud DNS.
- 2Click the name of the managed zone containing the record.
- 3Locate the dangling CNAME record row.
- 4Click the trash icon or select and click "Delete record set".
- 5Review the transaction change and apply.
Verification Checklist (RFC 7489)
Query DNS TXT record at _dmarc.yourcompany.com.
Ensure valid "p=" policy exists (transition from p=none to p=quarantine to p=reject).
Verify "rua=" tag points to an authenticated inbox or monitoring service.
Check alignment modes (aspf and adkim default to relaxed "r").
Live Validation Engine
Run Free DNS ValidatorValidate Your Google Cloud DNS DMARC Record
Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.