DMARC with no rua= — you are flying blind
The rua= tag tells receivers where to send daily aggregate reports listing who sent mail claiming to be your domain and whether it authenticated. Without it, you have no way to know whether moving to enforcement will break legitimate mail.
Adding it costs one tag and changes nothing about mail handling.
How to fix it
- 1Add rua=mailto:dmarc@yourdomain.com to the record.
- 2Use a dedicated mailbox — the reports are gzipped XML and arrive daily from every large receiver.
- 3If you point it at a third-party analytics service, verify their authorization record exists (see the external destination guide).
Check whether your domain has this problem
Free, no signup, about two seconds. You get the exact record to paste.
Related guides
- DKIM record with empty p= — a revoked key still in use
- SPF include points at a domain with no SPF record — a silent PermError
- DMARC record syntax errors that make receivers skip your policy
- DMARC external destination not authorized — why you receive no reports
- Two DMARC records at _dmarc — why your policy is being ignored