Skip to main content
dmarc PROTOCOLHost: Vercel DNSStandard: RFC 7489

How to Configure Domain-based Message Authentication, Reporting, and Conformance (DMARC) on Vercel DNS

Enforces receiver policy (none, quarantine, reject) when SPF and/or DKIM alignment fails, and generates forensic aggregate reports. Follow this verified implementation guide to deploy standard compliant DMARC DNS records in Vercel DNS.

Default DMARC Record Syntax

// Authoritative RFC Example
v=DMARC1; p=reject; rua=mailto:dmarc-reports@yourcompany.com; pct=100; aspf=r; adkim=r

Configuration Steps in Vercel DNS

  1. 1Open the Vercel Dashboard and navigate to the Team Settings or Project Settings.
  2. 2Go to "Domains" and select your root domain.
  3. 3Scroll to the DNS Records table.
  4. 4Find the CNAME record for the subdomain.
  5. 5Click the three dots menu (...) and select "Delete".

Verification Checklist (RFC 7489)

Query DNS TXT record at _dmarc.yourcompany.com.
Ensure valid "p=" policy exists (transition from p=none to p=quarantine to p=reject).
Verify "rua=" tag points to an authenticated inbox or monitoring service.
Check alignment modes (aspf and adkim default to relaxed "r").
Live Validation Engine

Validate Your Vercel DNS DMARC Record

Verify propagation, check syntax formatting, and audit recursive lookups in 60 seconds with SubDomainWatch.

Run Free DNS Validator