Who is sending as you, in plain English.

Ask for them, and every major email provider sends a daily report on mail using your domain name. They arrive as machine-readable files nobody can read, so we take them in, name every sender inside them, and go through the list with you each month.

Sender report● COLLECTING
RAW REPORTS IN · LAST 24H
google.com!acme.com!1721779200.xml.gz
outlook.com!acme.com!1721779200.xml.gz
yahoo.com!acme.com!1721779200.xml.gz
mail.ru!acme.com!1721779200.xml.gz
protonmail.ch!acme.com!1721779200.xml.gz
google.com!acme.com!1721779200.xml.gz
outlook.com!acme.com!1721779200.xml.gz
yahoo.com!acme.com!1721779200.xml.gz
mail.ru!acme.com!1721779200.xml.gz
protonmail.ch!acme.com!1721779200.xml.gz
READ AS NAMED SENDERS
Google Workspace
12,480PASS
Salesforce
3,204PASS
Mailchimp
1,890PASS
not recognised · mail.ru
412FLAGGED
EXAMPLE REPORT · ON A LOOPREVIEW READY
IN THE BASEDMARC Visualisation is one of the two halves of the Email Authentication base, so it is included rather than added on.See the whole of Email Authentication →
What the reports are

A daily report nobody can read.

DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is the rule you publish telling receiving mail systems what to do with mail that fails the checks on your domain, and the reporting half of that name is the part almost nobody uses. Switch it on and every major email provider starts sending you a file each day, listing every server that sent mail using your name, how much it sent, and whether it passed.

Those files arrive as XML, a format written for software rather than for people, and a single day can run to thousands of lines spread across dozens of separate files. Sitting in an inbox they answer nothing. Collected, added up and put in order, they are the only honest list of who is sending as you, which is the job we take on.

How it works

From unreadable file to named sender.

01

Collect

The daily reports from every major email provider sent to us, not to an inbox nobody opens.

02

Decode

The machine-readable files unpacked, de-duplicated, and added up across every provider.

03

Name

Each sending server matched to a tool you recognise, or flagged as one you do not.

04

Review

A written monthly review: what changed, what is new, and what needs a decision from you.

What's included

Everything you need, managed.

One agreement, one team, and a written review every month.

Daily reports collected from every major provider
Machine-readable files turned into named senders
Sending servers matched to the tools you use
New and unrecognised senders flagged
Volumes and pass rates for every sender
A written monthly review with your analyst
What you actually see

Every sender, named.

This is the same information the raw files carry, once they have been read. Every source that used your name in the period, how much it sent, and which checks it passed. Checks passed means which of the two checks that source cleared: SPF, the Sender Policy Framework list of servers allowed to send as you, and DKIM, the DomainKeys Identified Mail signature that proves a message was not altered on the way.

MONTHLY SENDER REPORT · SAMPLELAST 7 DAYS
17,986
Messages seen
4
Senders
412
Failed the checks
SourceVolumeChecks passedResult
Google Workspace12,480SPF + DKIMPASS
Salesforce3,204DKIM onlyPASS
Mailchimp1,890SPF onlyPASS
unknown sender (RU)412noneFAILED

A source we cannot place is a question, not proof of an attack. It is usually a tool somebody signed up for without telling anyone, a supplier sending on your behalf, or mail being forwarded, and naming it is how you tell those apart from someone actually faking you.

FAQ

See who is sending as you.