Included free with every account

DMARC monitoring, in plain English

Publish one address and we turn the cryptic XML aggregate reports mailbox providers send into readable dashboards — who’s sending as your domain, whether it passes SPF and DKIM alignment, and a safe path from monitoring to full p=reject enforcement.

No credit card. Point as many domains as you like at your reporting address.

What is DMARC monitoring?

DMARC lets you ask the world’s mailbox providers to report on mail claiming to be from your domain. When you add a rua (reporting URI for aggregate data) address to your DMARC record, providers send you a daily XML summary: which IPs sent mail as you, how much, and whether it passed SPF and DKIM alignment.

Those reports are the only way to see your real sending picture before you enforce a policy. The catch: they arrive as compressed XML from dozens of senders every day — unreadable by hand. This feature does the collecting, decompressing, parsing and aggregating so you just read the answers.

Why it matters

  • Stop spoofing. A p=reject policy stops criminals sending phishing as your domain — but only once you know it won’t also block your own mail.
  • Meet sender rules. Google and Yahoo’s bulk-sender requirements expect DMARC with reporting. See the compliance checker.
  • Find shadow senders. Reports reveal every tool sending as you — CRMs, invoicing apps, help desks — so none get left behind when you enforce.
  • Protect deliverability. Aligned, authenticated mail is trusted mail. Pair with the deliverability test.

What you get

Automatic report ingestion

Mailbox providers (Google, Microsoft, Yahoo and hundreds more) send daily aggregate reports as gzip/zip XML attachments. We receive, decompress and parse them for you — no scripts, no S3 bucket, no XML wrangling.

Readable dashboards

Every report becomes plain numbers: total messages, DMARC pass rate, and separate SPF-aligned and DKIM-aligned percentages over the last 90 days.

Sending-source intelligence

See every IP sending mail as your domain — how much it sends, its alignment rates, and which providers reported it. Spot the shadow-IT sender and the spoofer in the same table.

Check DNS verification

One click confirms your rua address is actually published in your _dmarc record, and flags a missing record, a missing rua, or a mismatch — so you never wait days for reports that were never going to arrive.

Active status you can trust

Once your DNS is verified, the domain shows a durable “Active” badge. You know at a glance that reporting is wired up correctly.

A safe path to enforcement

The whole point of monitoring is to reach p=reject without blocking real mail. The dashboard highlights failing-but-legitimate senders so you can fix alignment first, then tighten your policy with confidence.

How it works

Five steps, most of them one-time. You’ll be collecting reports the same day.

  1. 1
    Add your domain

    In your dashboard, open DMARC Monitor and add the domain you want to watch (for example example.com). We generate a unique reporting address for it.

  2. 2
    Publish the rua address

    Add the address we give you — <token>@dmarc.verifyany.email — to your domain’s _dmarc TXT record as a rua=mailto: tag. If you don’t have a DMARC record yet, our DMARC generator builds a safe starter record.

  3. 3
    Verify with Check DNS

    Click Check DNS. When your record resolves and lists our address, the domain flips to Active. If something’s off, you’ll get an exact reason (no record, no rua, or mismatch).

  4. 4
    Reports flow in

    Aggregate reports usually begin arriving within 24 hours and then land daily. Nothing else to run — new reports are parsed and rolled into your dashboard automatically.

  5. 5
    Review sources, then tighten

    Confirm every legitimate sender is SPF- or DKIM-aligned, fix the ones that aren’t, then ramp your policy from p=nonep=quarantinep=reject. Verify each change with the DMARC checker.

Reference & docs

The reporting address

Each domain you add gets its own address so reports are attributed correctly:

<token>@dmarc.verifyany.email

Where it goes in your DMARC record

Add it as a rua tag on your _dmarc.<domain> TXT record. A starter record looks like this — you can list several rua addresses, comma-separated:

Host:  _dmarc.example.com Type:  TXT Value: v=DMARC1; p=none; rua=mailto:<token>@dmarc.verifyany.email; fo=1; adkim=s; aspf=s

Start at p=none (monitoring only — changes nothing about delivery), review reports, then tighten. The DMARC generator builds this for you.

Check DNS statuses

StatusMeaning
ActiveRecord found and our rua address is published — reports will be collected.
rua missingA DMARC record exists but has no rua tag at all.
rua mismatchA rua is set, but our address isn’t among the listed ones — append it, comma-separated.
No DMARC recordNothing published at _dmarc.<domain> yet.
Multiple recordsMore than one DMARC record (invalid) — merge into one.

What the reports contain — and what they don’t

Aggregate (rua) reports are statistical: counts of messages per source IP with pass/fail results and the policy applied. They contain no message content and no recipient addresses. We ingest aggregate reports only. Data is retained for 90 days of trend history and tied to your account; remove a domain to delete its stored reports. See our data retention and privacy pages.

Frequently asked questions

Is DMARC monitoring really free?
Yes — it’s included with every account, including the free tier, for multiple domains. Create an account to start.
Do I need to change how I send email to use it?
No. At p=none it only collects reports and changes nothing about delivery. You control if and when you tighten to quarantine or reject.
How soon will I see data?
Usually within 24 hours of publishing the rua and confirming it with Check DNS — providers batch reports daily.
What is the difference between this and the DMARC checker tool?
The DMARC checker inspects your record once; monitoring collects the ongoing reports over time so you can see real senders and alignment before you enforce.
Do the reports include the contents of my emails?
No — aggregate reports are statistics only (counts and pass/fail per IP). No message content, no recipients. We ingest aggregate reports only.
How do I safely get to p=reject?
Confirm every real sender is aligned (fix the ones that aren’t), then step nonequarantinereject, re-checking with the DMARC checker each time. The dashboard flags what to fix first.

See who’s sending as your domain

Add a domain, publish one address, click Check DNS. You’ll have readable DMARC reports within a day — free.