DMARC monitoring that tells you the day something needs a new record
The scan finds what's wrong today. Monitor is the follow-up care: it re-reads your domains every day, reads the reports your receivers send back, tells you the day something breaks — and shows you when it's safe to tighten.
Not sure yet? Scan a domain first →
What Monitor watches
The registration and the certificate are read on every scan — the domain at 30, 14, 7 and 1 days out, the certificate at 14, 7 and 1. It is the outage nobody is monitoring for, because it isn't a mail problem until it is.
Every authentication record is diffed against the last good copy, so a contractor's quick fix over the weekend isn't discovered by a bounced invoice on Monday.
Your aggregate reports name every server sending as your domain. One that has never appeared before is surfaced once — and where reverse-DNS shows the hosts are siblings, a rotating cloud fleet folds into one finding rather than forty.
Your mail servers are checked against reputable blocklists through our own dedicated resolver, with a strict whitelist of listing codes — an ambiguous answer is reported as not checked rather than as a false alarm.
A check that was passing and now isn't — an over-limit lookup chain, a policy quietly weakened back to monitor-only — is an alert the same day, not a mystery next quarter.
Findings for a domain arrive batched — one message per check, not one per event — and the routine alert types can each be silenced if they aren't yours to act on. The two that mean your mail is already broken — a record that has been deleted, or a domain we can no longer read — always reach you.
Every sender, aligned or not
Publish a reporting address and every mailbox provider that supports DMARC reporting starts sending a daily report naming who sent as your domain. They arrive as compressed XML that nobody reads.
Monitor reads them for you and turns them into one table: each sending source, how much it sent, what share of it authenticated, and what receivers actually did with the rest. Sources you recognise get a name and stop asking for attention; the ones you don't stay flagged until you decide whether they are yours.

The safe path to a policy that actually blocks
Moving from monitor-only to quarantine, and then to reject, is not a setting you flip — it is a claim about your own mail. Get it wrong and you block your invoices, not the forgeries.
So Monitor earns it from evidence. Over a trailing 30-day window every known sender — the providers we recognise as well as the ones you have named yourself — has to be authenticating at least 99% of the time, and the volume nobody can account for — the part of it that isn't authenticating — has to stay under half a percent. Only then does the next step unlock, one rung at a time. An empty window is never treated as ready.
The record for that step is written by the same deterministic engine that writes the scanner's fixes — never by the AI layer, which only ever explains. You paste it yourself: we hold no write access to your DNS, and never will.

How it works
Paste it into the dashboard — up to ten of them. Nothing at your registrar changes yet: adding a domain just hands you the one record the next step needs.
Publish that TXT record, then press check. It proves the domain is yours — nobody can point our monitoring at someone else's mail. The first scan runs as soon as it checks out, so you have a grade and a diagnosis straight away.
Add our reporting address to your DMARC record. If you already have one, we merge it in so nothing else about the record changes; if you don't, we hand you a minimal monitor-only record to publish instead. Already sitting on an archive of reports? Upload it and the dashboard fills in instantly rather than waiting a day.
- 10 domains — enough for an agency's whole client roster
- Unlimited report volume and unlimited re-scans
- 12 months of history and report retention
- Every alert type on by default, and the routine ones silenceable one by one
The free scanner stays free, with or without a subscription. See the full plan comparison.
Common questions
What is DMARC monitoring?
Publishing SPF, DKIM and DMARC records is a one-time change; keeping them correct is not. Records get edited, new tools start sending as you, certificates and registrations lapse — and the reports receivers send back are the only place most of it is visible. Monitoring is the ongoing half: your domains are re-read every day, those reports are read for you, and you hear about a problem when it appears rather than when a customer says an email never arrived.
How is this different from reading my DMARC reports myself?
The reports arrive as compressed XML, one file a day from each provider that sends them, and they only describe what happened — never what to do about it. Monitor keeps them, turns them into one table of sending sources with volume and authentication share, folds a rotating cloud fleet — where reverse-DNS shows the hosts are siblings — into a single finding instead of forty, and pairs all of it with a daily re-read of the records themselves. It then uses that evidence to decide when tightening your policy is actually safe.
Do I need to give you access to my DNS?
No — and you cannot. Monitor reads your DNS from the outside, exactly as a receiving mail server does. Every record we generate is one you copy and publish yourself: there is no auto-apply, and we hold no write access. All you publish for us is a verification record proving the domain is yours, plus our reporting address in your DMARC record.
How quickly do alerts arrive?
Every monitored domain is re-scanned daily, and everything it finds — a changed record, a sender you have never seen, a blocklist listing, an approaching expiry — arrives as one message rather than one per finding. The routine alert types can each be switched off on their own; the two that mean your mail is already broken — a deleted record, or a domain we can no longer read — always reach you. Muting a finding in the dashboard stops it repeating.
What happens when the trial ends?
Monitoring pauses and your history stays visible in case you come back. The free scanner keeps working, and no card was taken, so nothing is charged.
Which DNS and email providers does it work with?
All of them. Everything is done from public DNS and from the aggregate reports that providers supporting DMARC reporting send back once you publish a reporting address. There is nothing to install and no provider has to support us specifically — if you can edit your domain's DNS records, wherever they are hosted, it works.