DMARC Engine
Home/Compare
Compare

DMARC Engine vs free tools & DIY

Free tools and DIY get you a record. The hard part, reaching enforced p=reject without breaking your mail, is what we do for you. Here is the honest comparison.

There are three honest ways to deal with DMARC. You can use free checkers and generators, including the ones we give away, to see where you stand and publish a record. You can roll your own enforcement in-house, reading the reports and turning the policy up yourself. Or you can hand the whole job to us. All three are legitimate, and for some domains the free tools are genuinely all you need. This page lays out exactly what each approach does and does not do, so you can pick the right one rather than the one with the loudest sales page.

We are going to be fair about this, because we have a stake in being trusted rather than just being chosen. The free tools are useful. DIY works if you have the time and the nerve. The reason a done-for-you service exists is not that the other two are useless, it is that the genuinely hard part of DMARC, the safe staged rollout and the report-reading underneath it, is the part free tools cannot do for you and the part DIY most often gets wrong.

The three approaches, in plain terms

Free tools and checkers

These tell you the state of things. A DMARC checker reads your current record and reports your policy value. A generator produces a syntactically correct record to paste into DNS. An SPF flattener counts your lookups and rewrites them to stay under the limit. We run a whole shelf of these for free, from a DMARC checker and SPF checker through to a BIMI logo validator, because every domain should be able to find out whether it is exposed without paying anyone. What free tools do not do is make decisions for you, watch your live traffic over time, or carry any responsibility for what happens when you change the record. They are instruments, not a process.

DIY, in-house

Here you do the work yourself. You publish p=none, point the rua tag at a mailbox, and start collecting aggregate reports. You read them, identify every system sending in your name, fix the ones that are not aligned, and then decide when it is safe to move to quarantine and reject. This is entirely doable. The DMARC, SPF and DKIM specifications are public, and a capable systems administrator can learn them. What DIY asks of you is time, attention spread over several weeks, and the confidence to change a live DNS record that, done wrong, can bounce your own invoices. The knowledge is free. The hours and the risk are not.

DMARC Engine, done-for-you

Here we do the rollout. We host your DMARC, SPF, DKIM, MTA-STS and BIMI records, ingest your aggregate reports for you, watch your live traffic, and walk your policy from p=none through quarantine to p=reject on a monitored schedule, timing each step against what the reports actually show. The deliverable is not a tool or a dashboard you have to interpret. It is the end state: an enforced domain, with no email outage along the way. The work described on our enforcement guide and audit page is the work we do, rather than instructions you follow.

What each approach actually does

The table below is the honest version. A tick means the approach does this for you; a partial note means it can help but leaves the real work to you. Read down the rows, not just across the columns, because the value is not evenly spread, most of it sits in the bottom half.

CapabilityFree toolsDIY in-houseDMARC Engine
Tells you if you are exposed Yes, this is exactly what they are for Yes, once you know what to read Yes, as the first step of the audit
Gets you a published record Generates the text; you paste it into DNS You write and publish it yourself We publish and host it for you
Expands SPF, keeps you under 10 lookups A flattener shows the count and a flattened record You maintain it as senders change Hosted and kept under the limit automatically
Reads aggregate (RUA) reports for you No, a one-off analyser parses a file you upload You collect and read them yourself, ongoing Yes, we ingest and interpret them continuously
Runs the staged none → quarantine → reject rollout No, a record is static text You decide and execute each move Yes, this is the core of the service
Watches live traffic and times each step No You watch and judge readiness yourself Yes, each step is paced against the reports
Aims for no email outage Not its job; the record is yours to break Depends entirely on your care and experience Yes, the whole method is built around this
Ongoing monitoring and alerts No, a check is a single moment in time You set up and watch your own monitoring Yes, continuous, with alerts when something changes
Multi-domain aggregation Check one domain at a time You stitch reports together yourself Yes, all your domains in one view
Cost and effort Free, but all the work and risk stay with you No fee; significant time over several weeks Flat fee plus monitoring; near-zero effort from you
Where the line really sits. The top four rows, checking, generating, flattening, and parsing a single uploaded report, are well covered by free tools. The bottom six, the staged rollout, the live watching, the outage-avoidance, and the ongoing monitoring across domains, are not things a tool can do. That is the dividing line between a checker and a service.

When free tools are genuinely enough

We mean this. If you run a single domain, send mail through one well-behaved provider such as Google Workspace or Microsoft 365 with nothing exotic bolted on, and you are comfortable reading a DNS record, the free tools can take you a long way. Run a free scan to see your policy, use a generator to produce a record, check your SPF lookups, and you have done the easy part competently and for nothing.

What the free tools cannot do is sit with you for the three weeks after you publish, while the aggregate reports trickle in, and tell you the difference between a forged message you want to block and a legitimate marketing platform you forgot you used. A one-off report analyser will parse a single file you upload, which is useful, but enforcement is not a single file. It is a stream of reports over time, read in context, with a decision at the end of each window about whether it is safe to tighten. That context is exactly what a static tool cannot hold, and it is the part that decides whether your invoices keep arriving.

A checker tells you the door is unlocked. It does not walk through your house, find everyone who has a key, and decide when it is safe to change the locks. That walk is the actual job.

When DIY makes sense, and where it tends to come unstuck

DIY is the right call when you have a genuinely skilled person with time to spare and an estate they already understand. If your administrator knows every system that sends in your name, can configure a custom DKIM signature inside each marketing platform, and can give the reports a regular eye for a few weeks, there is no reason they cannot reach p=reject on their own. The specifications are open and we link to the mechanics on our enforcement guide precisely because we have nothing to hide.

Where DIY comes unstuck is rarely the knowledge. It is three things that show up again and again. First, time: the reports need watching across weeks, and that attention is the first thing to slip when a real incident lands on the same desk. Second, the unknown sender: almost every domain discovers, on first inspection, a system nobody remembered, a payroll tool or an events platform mailing under its name, and missing it is how DIY rollouts bounce real mail. Third, nerve: p=none feels safe, so the policy quietly never advances, and the domain sits in monitor-only limbo for a year, exposed the entire time. We wrote about that specific trap on our guide to reaching enforcement, because it is the single most common DIY failure mode, and it is a failure of follow-through, not of understanding.

The honest DIY caveat. The danger of DIY is not usually a dramatic outage on day one. It is a record that reaches p=none and then stalls there forever, because nobody is sure it is safe to go further. A monitor-only record blocks nothing. If DIY means you never finish, you have the appearance of protection without the protection.

What the done-for-you service actually removes from your plate

The case for handing this over is not that we know secrets you cannot find. It is that we have removed the two things that stall DIY rollouts, the time and the risk, and turned them into a fixed, predictable engagement. We audit what you have, host the records so there is nothing for you to maintain, ingest your aggregate reports so there is nothing for you to read, and advance the policy step by step on a schedule that is paced against your real traffic rather than a calendar. If a step is not safe yet, we hold. If anything legitimate were ever caught, the record loosens in minutes, because it lives in a single DNS entry we control.

The outcome is the same destination DIY aims for, an aligned set of senders and a domain enforced at p=reject, but reached without you spending the weeks or carrying the worry. You can see the full set of records we host on the products page, and the precise sequence we follow on the enforcement guide. The short version: you keep doing your job, and your domain quietly stops being something a fraudster can wear. The same enforcement work is what closes the door on invoice and CEO fraud that spoofs your exact domain, and what satisfies the bulk-sender and compliance pressures in the next section.

Why this is not a someday job

Whichever approach you choose, the deadline is no longer hypothetical. Google and Yahoo's bulk-sender rules have required authentication since 1 February 2024, and Microsoft began applying the equivalent tightening to high-volume senders into Outlook.com, Hotmail and Live through 2025. PCI DSS 4.0 requirement 5.4.1 made anti-phishing controls mandatory from 31 March 2025. A monitor-only record does not satisfy the spirit of any of these. If you are going DIY, that is fine, but finish the rollout. If you would rather not own the clock, that is what we are for. The full list of what triggers the requirement is on our requirements page.

Pricing, in the open

No quote forms, no per-message metering, no surprise tiers. The done-for-you enforcement is a flat one-time fee, and monitoring is a simple monthly subscription. Here is the whole of it.

Enforcement (one-time)
£200 introductory, normally £500. Audit, hosting, and the full staged rollout to p=reject.
Monitoring (monthly)
£19/mo, normally £39. Ongoing report ingestion and alerts.
Free tools
£0, always. Checkers, generators and analysers, no account required.
DIY
No fee, but several weeks of your own time and the risk that comes with it.

Compare that honestly against DIY. DIY has no invoice attached, but it is not free: it costs the hours of a skilled person across several weeks, plus the risk that a missed sender bounces real mail, plus the very real chance the rollout stalls at p=none and never delivers the protection at all. For many organisations the flat fee buys back exactly the thing in shortest supply, the attention to finish the job safely.

The fair summary. Use the free tools to find out where you stand, today, at no cost. If you have the time and the confidence, do the rollout yourself, we have told you how. If you would rather it was simply done, on a fixed fee, with no outage and someone watching the reports, that is the service. All three are honest choices. We only sell the third because the first two leave the hardest part on your desk.

Ready to see your starting point? Run a free scan first, then read the enforcement guide to understand the rollout, glance at the FAQ if you have questions, and when you want it handled, start your enforcement at the introductory £200.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.