DMARC monitoring, in plain English
Publish one address and we turn the cryptic XML aggregate reports mailbox providers send into readable dashboards — who’s sending as your domain, whether it passes SPF and DKIM alignment, and a safe path from monitoring to full p=reject enforcement.
No credit card. Point as many domains as you like at your reporting address.
What is DMARC monitoring?
DMARC lets you ask the world’s mailbox providers to report on mail claiming to be from your domain. When you add a rua (reporting URI for aggregate data) address to your DMARC record, providers send you a daily XML summary: which IPs sent mail as you, how much, and whether it passed SPF and DKIM alignment.
Those reports are the only way to see your real sending picture before you enforce a policy. The catch: they arrive as compressed XML from dozens of senders every day — unreadable by hand. This feature does the collecting, decompressing, parsing and aggregating so you just read the answers.
Why it matters
- Stop spoofing. A
p=rejectpolicy stops criminals sending phishing as your domain — but only once you know it won’t also block your own mail. - Meet sender rules. Google and Yahoo’s bulk-sender requirements expect DMARC with reporting. See the compliance checker.
- Find shadow senders. Reports reveal every tool sending as you — CRMs, invoicing apps, help desks — so none get left behind when you enforce.
- Protect deliverability. Aligned, authenticated mail is trusted mail. Pair with the deliverability test.
What you get
Automatic report ingestion
Mailbox providers (Google, Microsoft, Yahoo and hundreds more) send daily aggregate reports as gzip/zip XML attachments. We receive, decompress and parse them for you — no scripts, no S3 bucket, no XML wrangling.
Readable dashboards
Every report becomes plain numbers: total messages, DMARC pass rate, and separate SPF-aligned and DKIM-aligned percentages over the last 90 days.
Sending-source intelligence
See every IP sending mail as your domain — how much it sends, its alignment rates, and which providers reported it. Spot the shadow-IT sender and the spoofer in the same table.
Check DNS verification
One click confirms your rua address is actually published in your _dmarc record, and flags a missing record, a missing rua, or a mismatch — so you never wait days for reports that were never going to arrive.
Active status you can trust
Once your DNS is verified, the domain shows a durable “Active” badge. You know at a glance that reporting is wired up correctly.
A safe path to enforcement
The whole point of monitoring is to reach p=reject without blocking real mail. The dashboard highlights failing-but-legitimate senders so you can fix alignment first, then tighten your policy with confidence.
How it works
Five steps, most of them one-time. You’ll be collecting reports the same day.
- 1Add your domain
In your dashboard, open DMARC Monitor and add the domain you want to watch (for example
example.com). We generate a unique reporting address for it. - 2Publish the rua address
Add the address we give you —
<token>@dmarc.verifyany.email— to your domain’s_dmarcTXT record as arua=mailto:tag. If you don’t have a DMARC record yet, our DMARC generator builds a safe starter record. - 3Verify with Check DNS
Click Check DNS. When your record resolves and lists our address, the domain flips to Active. If something’s off, you’ll get an exact reason (no record, no rua, or mismatch).
- 4Reports flow in
Aggregate reports usually begin arriving within 24 hours and then land daily. Nothing else to run — new reports are parsed and rolled into your dashboard automatically.
- 5Review sources, then tighten
Confirm every legitimate sender is SPF- or DKIM-aligned, fix the ones that aren’t, then ramp your policy from
p=none→p=quarantine→p=reject. Verify each change with the DMARC checker.
Reference & docs
The reporting address
Each domain you add gets its own address so reports are attributed correctly:
<token>@dmarc.verifyany.emailWhere it goes in your DMARC record
Add it as a rua tag on your _dmarc.<domain> TXT record. A starter record looks like this — you can list several rua addresses, comma-separated:
Host: _dmarc.example.com Type: TXT Value: v=DMARC1; p=none; rua=mailto:<token>@dmarc.verifyany.email; fo=1; adkim=s; aspf=sStart at p=none (monitoring only — changes nothing about delivery), review reports, then tighten. The DMARC generator builds this for you.
Check DNS statuses
| Status | Meaning |
|---|---|
| Active | Record found and our rua address is published — reports will be collected. |
| rua missing | A DMARC record exists but has no rua tag at all. |
| rua mismatch | A rua is set, but our address isn’t among the listed ones — append it, comma-separated. |
| No DMARC record | Nothing published at _dmarc.<domain> yet. |
| Multiple records | More than one DMARC record (invalid) — merge into one. |
What the reports contain — and what they don’t
Aggregate (rua) reports are statistical: counts of messages per source IP with pass/fail results and the policy applied. They contain no message content and no recipient addresses. We ingest aggregate reports only. Data is retained for 90 days of trend history and tied to your account; remove a domain to delete its stored reports. See our data retention and privacy pages.
Frequently asked questions
- Is DMARC monitoring really free?
- Yes — it’s included with every account, including the free tier, for multiple domains. Create an account to start.
- Do I need to change how I send email to use it?
- No. At
p=noneit only collects reports and changes nothing about delivery. You control if and when you tighten to quarantine or reject. - How soon will I see data?
- Usually within 24 hours of publishing the rua and confirming it with Check DNS — providers batch reports daily.
- What is the difference between this and the DMARC checker tool?
- The DMARC checker inspects your record once; monitoring collects the ongoing reports over time so you can see real senders and alignment before you enforce.
- Do the reports include the contents of my emails?
- No — aggregate reports are statistics only (counts and pass/fail per IP). No message content, no recipients. We ingest aggregate reports only.
- How do I safely get to p=reject?
- Confirm every real sender is aligned (fix the ones that aren’t), then step
none→quarantine→reject, re-checking with the DMARC checker each time. The dashboard flags what to fix first.
See who’s sending as your domain
Add a domain, publish one address, click Check DNS. You’ll have readable DMARC reports within a day — free.