There are three honest ways to deal with DMARC. You can use free checkers and generators, including the ones we give away, to see where you stand and publish a record. You can roll your own enforcement in-house, reading the reports and turning the policy up yourself. Or you can hand the whole job to us. All three are legitimate, and for some domains the free tools are genuinely all you need. This page lays out exactly what each approach does and does not do, so you can pick the right one rather than the one with the loudest sales page.
We are going to be fair about this, because we have a stake in being trusted rather than just being chosen. The free tools are useful. DIY works if you have the time and the nerve. The reason a done-for-you service exists is not that the other two are useless, it is that the genuinely hard part of DMARC, the safe staged rollout and the report-reading underneath it, is the part free tools cannot do for you and the part DIY most often gets wrong.
The three approaches, in plain terms
Free tools and checkers
These tell you the state of things. A DMARC checker reads your current record and reports your policy value. A generator produces a syntactically correct record to paste into DNS. An SPF flattener counts your lookups and rewrites them to stay under the limit. We run a whole shelf of these for free, from a DMARC checker and SPF checker through to a BIMI logo validator, because every domain should be able to find out whether it is exposed without paying anyone. What free tools do not do is make decisions for you, watch your live traffic over time, or carry any responsibility for what happens when you change the record. They are instruments, not a process.
DIY, in-house
Here you do the work yourself. You publish p=none, point the rua tag at a mailbox, and start collecting aggregate reports. You read them, identify every system sending in your name, fix the ones that are not aligned, and then decide when it is safe to move to quarantine and reject. This is entirely doable. The DMARC, SPF and DKIM specifications are public, and a capable systems administrator can learn them. What DIY asks of you is time, attention spread over several weeks, and the confidence to change a live DNS record that, done wrong, can bounce your own invoices. The knowledge is free. The hours and the risk are not.
DMARC Engine, done-for-you
Here we do the rollout. We host your DMARC, SPF, DKIM, MTA-STS and BIMI records, ingest your aggregate reports for you, watch your live traffic, and walk your policy from p=none through quarantine to p=reject on a monitored schedule, timing each step against what the reports actually show. The deliverable is not a tool or a dashboard you have to interpret. It is the end state: an enforced domain, with no email outage along the way. The work described on our enforcement guide and audit page is the work we do, rather than instructions you follow.
What each approach actually does
The table below is the honest version. A tick means the approach does this for you; a partial note means it can help but leaves the real work to you. Read down the rows, not just across the columns, because the value is not evenly spread, most of it sits in the bottom half.
| Capability | Free tools | DIY in-house | DMARC Engine |
|---|---|---|---|
| Tells you if you are exposed | Yes, this is exactly what they are for | Yes, once you know what to read | Yes, as the first step of the audit |
| Gets you a published record | Generates the text; you paste it into DNS | You write and publish it yourself | We publish and host it for you |
| Expands SPF, keeps you under 10 lookups | A flattener shows the count and a flattened record | You maintain it as senders change | Hosted and kept under the limit automatically |
| Reads aggregate (RUA) reports for you | No, a one-off analyser parses a file you upload | You collect and read them yourself, ongoing | Yes, we ingest and interpret them continuously |
| Runs the staged none → quarantine → reject rollout | No, a record is static text | You decide and execute each move | Yes, this is the core of the service |
| Watches live traffic and times each step | No | You watch and judge readiness yourself | Yes, each step is paced against the reports |
| Aims for no email outage | Not its job; the record is yours to break | Depends entirely on your care and experience | Yes, the whole method is built around this |
| Ongoing monitoring and alerts | No, a check is a single moment in time | You set up and watch your own monitoring | Yes, continuous, with alerts when something changes |
| Multi-domain aggregation | Check one domain at a time | You stitch reports together yourself | Yes, all your domains in one view |
| Cost and effort | Free, but all the work and risk stay with you | No fee; significant time over several weeks | Flat fee plus monitoring; near-zero effort from you |
When free tools are genuinely enough
We mean this. If you run a single domain, send mail through one well-behaved provider such as Google Workspace or Microsoft 365 with nothing exotic bolted on, and you are comfortable reading a DNS record, the free tools can take you a long way. Run a free scan to see your policy, use a generator to produce a record, check your SPF lookups, and you have done the easy part competently and for nothing.
What the free tools cannot do is sit with you for the three weeks after you publish, while the aggregate reports trickle in, and tell you the difference between a forged message you want to block and a legitimate marketing platform you forgot you used. A one-off report analyser will parse a single file you upload, which is useful, but enforcement is not a single file. It is a stream of reports over time, read in context, with a decision at the end of each window about whether it is safe to tighten. That context is exactly what a static tool cannot hold, and it is the part that decides whether your invoices keep arriving.
A checker tells you the door is unlocked. It does not walk through your house, find everyone who has a key, and decide when it is safe to change the locks. That walk is the actual job.
When DIY makes sense, and where it tends to come unstuck
DIY is the right call when you have a genuinely skilled person with time to spare and an estate they already understand. If your administrator knows every system that sends in your name, can configure a custom DKIM signature inside each marketing platform, and can give the reports a regular eye for a few weeks, there is no reason they cannot reach p=reject on their own. The specifications are open and we link to the mechanics on our enforcement guide precisely because we have nothing to hide.
Where DIY comes unstuck is rarely the knowledge. It is three things that show up again and again. First, time: the reports need watching across weeks, and that attention is the first thing to slip when a real incident lands on the same desk. Second, the unknown sender: almost every domain discovers, on first inspection, a system nobody remembered, a payroll tool or an events platform mailing under its name, and missing it is how DIY rollouts bounce real mail. Third, nerve: p=none feels safe, so the policy quietly never advances, and the domain sits in monitor-only limbo for a year, exposed the entire time. We wrote about that specific trap on our guide to reaching enforcement, because it is the single most common DIY failure mode, and it is a failure of follow-through, not of understanding.
p=none and then stalls there forever, because nobody is sure it is safe to go further. A monitor-only record blocks nothing. If DIY means you never finish, you have the appearance of protection without the protection.What the done-for-you service actually removes from your plate
The case for handing this over is not that we know secrets you cannot find. It is that we have removed the two things that stall DIY rollouts, the time and the risk, and turned them into a fixed, predictable engagement. We audit what you have, host the records so there is nothing for you to maintain, ingest your aggregate reports so there is nothing for you to read, and advance the policy step by step on a schedule that is paced against your real traffic rather than a calendar. If a step is not safe yet, we hold. If anything legitimate were ever caught, the record loosens in minutes, because it lives in a single DNS entry we control.
The outcome is the same destination DIY aims for, an aligned set of senders and a domain enforced at p=reject, but reached without you spending the weeks or carrying the worry. You can see the full set of records we host on the products page, and the precise sequence we follow on the enforcement guide. The short version: you keep doing your job, and your domain quietly stops being something a fraudster can wear. The same enforcement work is what closes the door on invoice and CEO fraud that spoofs your exact domain, and what satisfies the bulk-sender and compliance pressures in the next section.
Why this is not a someday job
Whichever approach you choose, the deadline is no longer hypothetical. Google and Yahoo's bulk-sender rules have required authentication since 1 February 2024, and Microsoft began applying the equivalent tightening to high-volume senders into Outlook.com, Hotmail and Live through 2025. PCI DSS 4.0 requirement 5.4.1 made anti-phishing controls mandatory from 31 March 2025. A monitor-only record does not satisfy the spirit of any of these. If you are going DIY, that is fine, but finish the rollout. If you would rather not own the clock, that is what we are for. The full list of what triggers the requirement is on our requirements page.
Pricing, in the open
No quote forms, no per-message metering, no surprise tiers. The done-for-you enforcement is a flat one-time fee, and monitoring is a simple monthly subscription. Here is the whole of it.
p=reject.Compare that honestly against DIY. DIY has no invoice attached, but it is not free: it costs the hours of a skilled person across several weeks, plus the risk that a missed sender bounces real mail, plus the very real chance the rollout stalls at p=none and never delivers the protection at all. For many organisations the flat fee buys back exactly the thing in shortest supply, the attention to finish the job safely.
Ready to see your starting point? Run a free scan first, then read the enforcement guide to understand the rollout, glance at the FAQ if you have questions, and when you want it handled, start your enforcement at the introductory £200.