Build a valid SPF, DMARC, DKIM or MTA-STS record from a form, then paste it into your DNS. Everything is assembled in your browser, nothing you type here is sent anywhere, including to us.
.
Host names are shown the way most DNS panels expect them. A few providers
want the full name including your domain, if yours shows an existing record as
_dmarc.yourdomain.com rather than _dmarc, use the full form.
Yes. p=none changes nothing about delivery; it turns on reporting so you can see every source sending as your domain. Enforce (quarantine, then reject) only after two or more weeks of reports show all legitimate senders passing.
rua is the address that receives aggregate reports, and without it DMARC tells you nothing. Point it at a mailbox or a monitoring service you will actually read.
Only if a legitimate sender is failing alignment, which is exactly what the p=none reporting phase exists to surface first. Fix the failing source, then enforce.