Enter your domain: in 8 seconds you'll know whether anyone can send email as you, and what to change — in plain English, no jargon.
DMARC is the setting that tells mailbox providers (Gmail, Outlook, Yahoo…) what to do with an email that claims to come from your domain without proof. Without it, anyone can write to your customers from your address: a fake invoice, fake bank details — and it's your name that takes the hit.
It isn't a rare situation: most small-business domains still have no DMARC record at all, and Gmail and Yahoo now require one from regular senders. Checking DMARC tells you, in 8 seconds, which side you're on.
Your DMARC record carries a policy, written p=. p=none: you observe, but fake emails still get through. p=quarantine: fakes land in the recipient's spam folder. p=reject: fakes are refused — your name is locked down.
An sp= tag can weaken the protection on your subdomains (billing.your-domain.com, say). The scan catches that too.
The rua=mailto: tag tells mailbox providers where to send, every day, the summary of who sent email in your name. Without it you're flying blind: you'll never know someone is spoofing you, or that one of your own tools is sending badly.
Those reports are also what show whether your legitimate email is "aligned" (SPF or DKIM passing under your domain) — the condition for moving to blocking without breaking your real email.
Whether the _dmarc record exists, whether its syntax is readable (a valid policy), the policy for the domain and its subdomains, and whether a reporting address is set. It also checks SPF and DKIM, which DMARC relies on, and gives you a score out of 100 with a plain list of what's wrong.
What it can't see from your DNS: whether your real email is aligned, and who is sending in your name right now. Only the reports tell you that — which is exactly what monitoring collects for you, day after day.
If your domain sits at p=none, we explain how to move to p=reject without breaking anything, step by step.
It's a start: you receive reports, but fake emails still get through. p=none is the observation stage, not protection. Once your reports show your legitimate email authenticates correctly, move to quarantine, then reject.
Nothing tells mailbox providers to refuse an email that spoofs your name. They fall back on their own filters, and your own email lands in spam more easily — Gmail and Yahoo now require DMARC from regular senders.
In your domain's DNS zone, at whoever manages it (GoDaddy, Namecheap, Cloudflare, Squarespace…): a TXT record named _dmarc. Our guides give the exact click path for each host.
You can, but it's risky: if one of your tools sends without being properly declared, its email will be refused. Better to collect reports for a few weeks, fix what's missing, then tighten the policy.
Yes: no signup, no credit card, as many times as you like. Only daily monitoring with a weekly bulletin is paid.
The scan is free and needs no signup; if you want your domain watched every day with a weekly bulletin, monitoring starts at €25/month + tax — see pricing.