Skip to content
SysGlass

DMARC monitoring

See who's sending as your domain. Add your domain, point its DMARC rua at the address we give you, and we turn the daily aggregate reports receivers send into clear charts — message volume, DMARC pass/fail over time, and the exact source IPs failing alignment (your spoofers, or your own misconfigured senders). The data you need to safely reach p=reject. Free.

Tip: sign in (top right) to save your domains to your account instead of just this browser.

How it works

  • Add a domain and get a unique rua address that belongs to it.
  • Append it to your DMARC record at _dmarc.yourdomain.com — keep any existing p= policy, just add the reporting address.
  • Receivers (Google, Microsoft, Yahoo and others) send daily aggregate reports to that address.
  • We ingest and store them over time, so trends build up — the charts fill within about 24 hours.
  • Optionally prove ownership with a TXT record; it's also auto-confirmed when your first report arrives.

What you get

  • Total message volume and your overall DMARC pass rate over a 30-day window.
  • Separate DKIM and SPF alignment rates, shown as gauges.
  • A day-by-day chart of pass vs fail volume, so trends and spikes are obvious.
  • Receiver dispositions — what mailbox providers actually did with failing mail (none / quarantine / reject).
  • Top sending source IPs, each with its pass/fail breakdown — your spoofers and your own misconfigured senders.
  • The reporting organizations that sent the data.
  • Plain-language alerts that flag when something needs attention, such as a drop in pass rate.

How to read it

  • A pass rate near 100% across all of your legitimate senders means it's safe to advance toward p=reject.
  • A failing source IP that's yours (an ESP, app, or marketing platform) means: add it to SPF and enable aligned DKIM for it.
  • A failing source IP you don't recognize is most likely spoofing — DMARC at p=quarantine or p=reject will stop it.
  • The disposition counts show whether receivers are currently rejecting, junking, or still delivering your failing mail.

Frequently asked questions

What is DMARC monitoring and why do I need it?

DMARC monitoring continuously collects the daily aggregate (rua) reports that receivers like Google, Microsoft and Yahoo send about your domain, and turns them into charts. It shows every source sending as your domain — your own services and any spoofers — and whether each one passes DMARC alignment. You need it to see who is using your domain before you tighten your policy to p=reject, so you don't accidentally block your own legitimate mail.

How do I set it up?

Add your domain and we give you a unique rua address. Append it to your DMARC record at _dmarc.yourdomain.com (for example v=DMARC1; p=none; rua=mailto:...). If you already have a DMARC record, keep your existing policy and just add the rua address. Receivers then start sending daily aggregate reports, and the charts fill in within about 24 hours.

Do I have to change my DMARC policy to p=none?

No. If you already publish p=quarantine or p=reject, keep it — you only add (or append to) the rua= reporting address. Monitoring works at any policy level. p=none is only suggested for domains that have no DMARC record yet, so you can watch the reports for a while before you start enforcing.

What do the charts show me?

Total message volume over the last 30 days, your overall DMARC pass rate, how many messages are failing, separate DKIM and SPF alignment rates, a day-by-day pass/fail volume chart, what receivers actually did with failing mail (none, quarantine or reject), and your top sending source IPs with each one's pass/fail split. The failing sources are your action list.

Is it really free, and do I need an account?

Yes — it's free with no per-domain fee. You can monitor anonymously, with the domain kept in this browser via a local read secret. Signing in binds your monitored domains to your account so you can reach them from any device and don't depend on browser storage.

How does ownership verification work?

It's optional but recommended. We give you a TXT record to add to your DNS; click Verify ownership and we check for it. Ownership is also confirmed automatically as soon as your first aggregate report arrives, since reports only flow to a rua address you control.

Other tools