DMARC Engine
Home/Documentation/The dashboard explained
Documentation

The dashboard explained

A guided, click-by-click tour of the DMARC Engine dashboard home: the stats row, the Overall Compliance gauge, the Daily Pass/Fail trend chart, Quick Actions, the five-service grid, Recent Activity, Setup Completeness, Pending Setup, Active Alerts, the empty states and Retry behaviour, and the onboarding screen for brand-new accounts.

22 June 2026 · 12 min read

The dashboard at a glance

The dashboard home is the first screen you see after signing in to https://app.dmarcengine.com. It lives at the root path (/), so any time you click the DMARC Engine logo or the Dashboard item in the left-hand navigation, this is where you land.

The home screen exists to answer one question quickly: how protected is my email right now, and what is the single most useful thing I can do next. Everything on the page is arranged to serve that question. There are no settings to change here; it is a read-only overview that links you out to the pages where the real work happens.

This guide walks the page top to bottom, region by region, naming every panel, number, button and badge, and explaining what each one means and where it takes you. Keep the dashboard open in another tab as you read, so you can match each description to what is in front of you.

If you have only just created your account and have not added a domain yet, you will not see most of these panels. You will see a much simpler onboarding screen instead. That state is covered at the end, under The onboarding state. If you have at least one domain, read straight through.

New to the platform entirely? Read Getting started first for sign-in, two-factor authentication and the big picture, then come back here for the detailed tour.

The stats row

Across the very top of the dashboard sit four headline figures. These summarise your whole account, not one individual domain, so they roll up every domain you have added.

  • Domains is the total count of domains on your account, whether they are verified or still pending verification. It is the quickest way to confirm the account holds what you expect. Adding or removing a domain on the Domains page changes this number.
  • Total Emails (30d) is the volume of mail seen across all your domains over the last thirty days. This figure is drawn from the aggregate (RUA) reports that receiving mail servers send back to you, so it only begins to fill in once reporting is flowing. A brand-new domain shows nothing here at first; that is expected, not a fault. Once reports arrive (usually within a day or two of delegation) the number starts to climb.
  • DMARC Compliance is the percentage of that mail which passed DMARC: in other words, mail that passed SPF or DKIM with correct alignment. This is the single most important number on the entire dashboard. A low or even zero figure is completely normal on day one, because your legitimate sending sources have not yet been brought into alignment and you are deliberately sitting at a monitoring-only policy. The figure rises as you align each sender.
  • Threat events detected counts the suspicious or failing activity the platform has flagged across your domains, such as a sudden burst of failures from an unfamiliar sending source, or mail that fails authentication from an IP you have never used. Clicking this card takes you through to the Threats view for the detail behind the count.

Read the stats row left to right and you have a one-line summary of your account: how many domains, how much mail, how much of it is trustworthy, and how much looks hostile.

The Overall Compliance gauge

Beneath the stats row sits the Overall Compliance gauge, a dial that runs from 0 to 100 per cent. It is the visual form of your compliance figure, weighted across all your domains, and it is meant to be your at-a-glance health indicator: green and high is good, low is work to do.

When you first onboard a domain the gauge will sit low. That is by design, not a problem. At the start your sending sources are not yet aligned, and your DMARC policy is deliberately set to monitoring only (p=none) so that nothing legitimate can be blocked while you learn. As you work through each sending source and bring it into SPF or DKIM alignment, the gauge climbs.

The rule of thumb is simple: you want the gauge high and steady before you tighten enforcement. Moving a domain from monitoring to quarantine, and later to reject, while the gauge is still low risks blocking real mail that has not yet been aligned. For the full method behind raising this number safely, see The enforcement journey.

Daily Pass/Fail Trend

Next is the Daily Pass/Fail Trend chart, a line graph that plots, day by day, how much of your mail passed DMARC against how much failed. Where the gauge gives you a single number for today, this chart gives you the direction of travel over time.

This is the panel you watch after making a change. Add a missing sending source to your SPF record, for example, and over the following days, as fresh aggregate reports arrive, you should see the fail line fall and the pass line rise. Because reports are batched and sent back by receivers on their own schedule (typically once a day), the chart updates gradually rather than instantly. Give any change a few days to show through here before concluding it did not work.

A View analytics link sits beside the chart. It opens the fuller analytics view, where the same pass and fail data can be broken down by sending source, by authentication result and by individual domain. Use the home chart to spot the trend; use the analytics page to find out exactly which source or which domain is driving it.

If reporting has not started yet, this panel shows an "awaiting report data" empty state rather than a chart. That is normal for a freshly delegated domain and clears itself once reports begin to arrive.

Quick Actions

Below the chart is a row of Quick Actions: four buttons that jump you straight to the tasks people perform most often, so you do not have to hunt through the navigation.

  • Add Domain opens the Domains page and its add-domain wizard, ready for you to protect another domain. This is the fastest route from the home screen to onboarding something new. The full walkthrough is in Adding your first domain.
  • DNS Check opens the Lookup tool, where you can inspect the live, currently published DNS records for any domain: its DMARC, SPF, DKIM, MTA-STS and BIMI records as the rest of the internet sees them right now. Use it to confirm a change has propagated, or to check a domain before you add it.
  • Generate Report opens the Reports page, where you can produce a shareable summary of authentication status and compliance, useful for handing to a manager, a client or an auditor.
  • View Threats opens the Threats page, the same destination as the threat events stat card, listing the suspicious activity the platform has detected so you can investigate it.

Treat Quick Actions as shortcuts. Everything they reach is also available from the left-hand navigation, but these four are the ones worth a single click from home.

The services grid

The heart of the dashboard is the services grid: five cards, one for each of the email-authentication standards the platform manages. They run in the order you should generally think about them.

  • DMARC is the policy layer that ties everything together and tells receivers what to do with mail that fails authentication. Its card links to the DMARC page. Background reading: Hosted DMARC and Understanding your DMARC record.
  • SPF lists which servers are allowed to send mail for your domain. Its card links to the SPF page. See Hosted SPF and, for the flattening that keeps you under the ten-lookup limit, How SPF flattening works.
  • DKIM cryptographically signs your mail so receivers can confirm it was not tampered with in transit. Its card links to the DKIM page. See Hosted DKIM.
  • MTA-STS enforces encrypted, authenticated delivery between mail servers so messages cannot be silently downgraded to plain text. Its card links to the MTA-STS page.
  • BIMI is the reward at the end of the journey: your verified logo displayed beside your mail in supported inboxes. Its card links to the BIMI page. See Hosted BIMI. BIMI will not display until your DMARC policy is enforced, so do not expect it to do anything until the rest is done.

Each card is both a status indicator and a doorway. The card reflects how that service is doing across your account, and clicking it takes you to the dedicated page where you configure and monitor it. If you are not sure where to start, work the grid left to right: DMARC, SPF and DKIM are the foundation, MTA-STS hardens transport, and BIMI comes last.

Want a definition for any of these before you click in? The glossary has a plain-English entry for every standard and term used across the dashboard.

Recent Activity

Lower on the page is the Recent Activity panel, a running log of recent changes and events on your account: records published, settings changed, domains added and similar actions. It is there so you can see at a glance what has happened lately, which is particularly useful when more than one person manages the account.

A View all link opens the full audit log, which holds the complete, time-stamped history rather than just the latest few entries. The audit log is an administrator view, so the View all link and the full log are available to users with an administrator role; see Team and roles for who can see what. If your account is quiet, the panel simply shows the most recent items it has, or nothing if there is no activity yet.

Setup Completeness

The Setup Completeness matrix is the panel that tells you, per domain, exactly how far through configuration you are. Each row is one of your domains, and against it sit five status badges, one for each service, labelled by their initials:

  • D for DMARC
  • S for SPF
  • K for DKIM
  • M for MTA-STS
  • B for BIMI

Each badge shows whether that service is set up and active for that domain, so a fully protected domain shows all five lit, while a domain you only added this morning may show just one or two. Reading across a row tells you what a single domain still needs; reading down a column tells you which service you have been neglecting across the whole account.

This matrix is the fastest way to find gaps. If you have ten domains and the K column is mostly empty, you know DKIM is your next job. If one domain is lit across all five badges and another is nearly blank, you know exactly where to spend the next hour. Click into any service from the services grid above, or open the domain from the Domains page, to fill in the missing badges.

Pending Setup

The Pending Setup panel is the dashboard's to-do list. It surfaces the domains and services that still need attention: a domain you have added but not yet verified, a record you have generated but not yet published, or a service that has been started but not finished. Where Setup Completeness shows you the whole grid, Pending Setup pulls out just the items that are not done, so you do not have to scan for them.

A View all link opens the Domains page, where you can pick up each outstanding item and finish it. If everything you have started is complete, this panel is empty, which is exactly what you want to see. Working this panel down to nothing, domain by domain, is the most direct path to a fully protected account.

Active Alerts

The Active Alerts panel shows notifications that currently need your attention: things the platform has flagged as worth knowing about right now, such as a record that has stopped resolving, a sudden change in authentication results, or a configuration that has drifted from what it should be. These are live alerts, not historical ones, so the panel reflects the present state of your domains.

A View all link opens the Alerts page, where you can see the full list, review each alert in detail and manage how you are notified. To choose which events raise an alert and where those notifications are sent (email, and other channels you configure), see Setting up alerts.

When there is nothing to report, the panel shows a "no active alerts" empty state. On a healthy, well-configured account that is the normal resting state, and seeing it is good news rather than a sign that something is missing.

Empty states and the Retry button

Several panels on the dashboard depend on data that takes time to arrive or is simply not there yet on a new account. Rather than showing a broken or blank box, each one shows a clear, friendly empty state so you always know whether you are looking at "nothing has happened" or "something has gone wrong".

  • The Daily Pass/Fail Trend shows an "awaiting report data" message until aggregate reports start arriving for your domains. This is normal for the first day or two after delegating DNS, and clears on its own.
  • The Threats stat and panel show a "no recent threat activity" empty state when nothing suspicious has been detected. On a quiet, well-protected account this is the expected and desirable state.
  • The Active Alerts panel shows a "no active alerts" empty state when there is nothing outstanding.

If a panel genuinely fails to load its data (for example, a temporary network hiccup between your browser and the platform), it shows a data error with a Retry button rather than an empty state. Clicking Retry asks the dashboard to fetch that data again, which clears most transient errors. If Retry keeps failing on the same panel, that points to a real problem rather than a blip, and it is worth raising with support.

Knowing the difference matters: an empty state means there is simply nothing to show yet, and you should leave it to fill in over time, whereas a Retry button means the fetch failed and you should try again.

The onboarding state

If you have not yet added any domains, the dashboard does not show the stats, gauge, chart and panels described above. There is nothing to populate them with, so instead you see a focused onboarding card built to get you moving. It offers two buttons:

  • Add Your First Domain takes you straight into the add-domain wizard. This is the recommended starting point for a new account: it is where you tell the platform which domain you are protecting and prove that you control it. The wizard is documented step by step in Adding your first domain.
  • Check a Domain lets you run a quick, read-only lookup of a domain's current DNS first, using the same engine as the Lookup tool. It is handy if you want to see the state of a domain's existing DMARC, SPF and DKIM records before you commit to onboarding it, with no changes made to anything.

Most people should click Add Your First Domain and follow the wizard. As soon as your first domain is added and starts reporting, the full dashboard described in this guide appears, and the onboarding card is replaced by the live overview.

Prefer to look before you leap? Our free, no-login tools let you inspect any domain from outside the platform: the DMARC checker, SPF checker, DKIM checker, MTA-STS checker and BIMI checker. To read a raw aggregate report you already have, use the DMARC report analyzer, and to draft a policy by hand, the DMARC generator.

Where to go next

The dashboard is a map, not a destination. Once you understand it, your day-to-day rhythm is simple: glance at the Overall Compliance gauge and the stats row to take the temperature, scan Pending Setup and Active Alerts for anything that needs doing, use Setup Completeness to find the next gap, and click into the relevant service to close it.

From here, the natural next steps are:

If a term anywhere on the dashboard is unfamiliar, the glossary defines it, and the requirements page explains what mailbox providers such as Google, Yahoo and Microsoft now expect, which is the reason all of this matters.

Share

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.