Who is sending as you, in plain English.
Ask for them, and every major email provider sends a daily report on mail using your domain name. They arrive as machine-readable files nobody can read, so we take them in, name every sender inside them, and go through the list with you each month.
A daily report nobody can read.
DMARC stands for Domain-based Message Authentication, Reporting and Conformance. It is the rule you publish telling receiving mail systems what to do with mail that fails the checks on your domain, and the reporting half of that name is the part almost nobody uses. Switch it on and every major email provider starts sending you a file each day, listing every server that sent mail using your name, how much it sent, and whether it passed.
Those files arrive as XML, a format written for software rather than for people, and a single day can run to thousands of lines spread across dozens of separate files. Sitting in an inbox they answer nothing. Collected, added up and put in order, they are the only honest list of who is sending as you, which is the job we take on.
From unreadable file to named sender.
Everything you need, managed.
One agreement, one team, and a written review every month.
Every sender, named.
This is the same information the raw files carry, once they have been read. Every source that used your name in the period, how much it sent, and which checks it passed. Checks passed means which of the two checks that source cleared: SPF, the Sender Policy Framework list of servers allowed to send as you, and DKIM, the DomainKeys Identified Mail signature that proves a message was not altered on the way.
A source we cannot place is a question, not proof of an attack. It is usually a tool somebody signed up for without telling anyone, a supplier sending on your behalf, or mail being forwarded, and naming it is how you tell those apart from someone actually faking you.
Reporting is one part of the email side.
The service that sets the records up and takes DMARC all the way to blocking, the record work these reports tell you is needed, and the logo step that only starts once blocking is stable. Anything you take on runs under one agreement with one team.
Email authentication
SPF and DMARC set up and managed, with DMARC set to block and monitored, so mail faking your exact address is refused rather than delivered. Every sender checked for a valid signature, and your verified logo in inboxes once blocking is stable.
Learn more →Managed SPF
Two jobs on one record. Hardening removes the lookups that resolve to nothing and the entries authorising tools you no longer send from. Flattening rewrites a record still over the ten-lookup limit into one that passes.
Learn more →BIMI certification
Your verified logo beside your mail in the inboxes that support it, including the Verified Mark Certificate it depends on. The last step once DMARC is set to block.
Learn more →