DMARC monitoring with full data ownership
Know who's sending email as your domain with record-level detail, actionable guidance, and deployment options that keep your data yours — plus a header analyzer that checks whether an individual message is what it claims to be.
The header analyzer is free to use — no signup, no login.
What is DMARC monitoring?
Every day, email providers like Google, Microsoft, and Yahoo send DMARC aggregate reports to domain owners. These XML reports reveal who is sending email as your domain and whether those messages pass authentication checks. Most organizations never read them.
Collect
Connect your DMARC inbox or use a managed email collector, and dmarco automatically fetches, parses, and preserves every individual record from every reporting organization.
Analyze
Drill into every DMARC record — per source IP, per authentication result, per message count. Identify exactly which senders are authorized and which are unknown, with full detail instead of aggregated summaries.
Protect
Get actionable recommendations to move from monitoring (p=none) to enforcement (p=reject), with data-backed confidence that legitimate senders are accounted for.
Beyond DMARC: email safety analysis
DMARC tells you who is authorized to send from your domain. It cannot tell you whether a message sitting in an inbox is honest. dmarco does both — report ingestion across your domains, and a phishing-aware header analyzer for individual messages.
Half one: DMARC visibility
The reports are already being sent. dmarco collects them, parses every record, enriches each IP with reverse DNS, ASN, and geolocation, and cross-references a maintained library of known senders — so you can see exactly who is sending as your domain.
This is the traditional half of a DMARC product. It answers who sends as us, and does it authenticate?
Half two: email-safety analysis
Report data says who can authenticate. A DMARC-authenticated message can still be phishing — from a compromised marketing account, a mailing-list forward, a lookalike link. The header analyzer reads one message's headers and body and runs seven layers of check on top of DMARC's answer.
This is the half most DMARC products don't offer. It answers can I trust this specific message?
Free, no signup. See the seven detection layers or read the email-safety overview. The analyzer is one layer of defense — it reports the patterns it can see in a message, not a guarantee that a message is safe.
Everything you need for DMARC compliance
Record-Level Detail
Every DMARC record is stored individually — source IP, SPF result, DKIM result, alignment, and message count. Drill into the data instead of relying on rolled-up percentages.
Sender Attribution & Geolocation
Identify senders by IP, reverse DNS, ASN, country, and city. Match against known providers like Google Workspace, Microsoft 365, Mailgun, SendGrid, and more.
SPF & DKIM Validation
Live DNS diagnostics for your DMARC and SPF records. See which senders are SPF-authorized and track SPF changes over time.
Per-Domain Sender Review
Approve or flag senders on a per-domain basis. Know which providers are expected for each domain and get alerted when unknown senders appear.
Policy Progression Guidance
Data-driven recommendations for when to move from p=none to p=quarantine to p=reject. Requires reviewed senders, sufficient history, and high pass rates before suggesting changes.
Email Alerts & Webhooks
Get notified of unknown senders, SPF/DKIM failure spikes, SPF record changes, and volume anomalies via email or webhooks. RFC 8058 compliant one-click unsubscribe.
Data Ownership
Your DMARC data belongs to you. Export it, inspect every record, and retain full control. Data ownership is included on every plan — not locked behind an enterprise tier.
Multi-Domain, Multi-Tenant
Monitor dozens of domains across multiple organizations. Each org gets isolated data, configurable settings, and its own sender review workflow.
Learn DMARC and email safety at your own pace
Practical guides for DMARC and SPF decisions — when to tighten policy, how to identify legitimate senders, how to communicate changes to your team — and for the phishing patterns that survive a clean DMARC pass.