RFC 9989 policy discovery

DMARC DNS Tree Walk Explorer

Trace the bounded DNS Tree Walk that determines DMARC Organizational Domain boundaries under the current standard.

dmarc dns tree walkrfc 9989 checkerdmarc organizational domaindmarc policy discovery
Trace the RFC 9989 DMARC DNS Tree Walk Reads public DMARC TXT records only. The walk is bounded to the standard's eight-query maximum.

What this analysis does

Enter any real domain to inspect each _dmarc lookup in the RFC 9989 Tree Walk, see which valid policies were discovered, identify psd=n or psd=y boundaries, and understand why a particular Organizational Domain is selected.

How to use the result

Use real evidence

Paste the exact domain, header, message or configuration. The result is only as useful as the evidence supplied.

Review the findings

Mailybox separates observations from inferred causes so you can see what is known and what still needs verification.

Retest after changes

Email authentication and routing are stateful. Re-run the analysis after publishing a fix.

Interpretation matters

Email systems combine DNS, message-level evidence, provider policy and intermediate infrastructure. A single passing check is not proof that every message will deliver, and a single warning is not proof that a domain is misconfigured. Mailybox is designed to expose the evidence and the relationship between signals so the next action is clear.

Primary references