21 June 2026 · 2 min read
DMARC Engine is a done-for-you hosted platform for email authentication. It manages the full stack that proves your mail is really from you: DMARC, SPF, DKIM, MTA-STS and BIMI. Instead of leaving you to hand-edit DNS records, decipher cryptic aggregate reports and hope nothing breaks, we host those records on Cloudflare's network and walk your domain through a safe, staged rollout. The goal is concrete: get you from p=none (monitoring only, no protection) to p=reject (spoofed mail is rejected at the recipient's server) without a single legitimate message going missing along the way. You delegate a few records to us once, and from then on we maintain them, watch the incoming reports and tell you exactly when it is safe to tighten policy.
The "done-for-you" part is the point. Getting to p=reject by hand is genuinely fiddly. SPF has a hard limit of ten DNS lookups that large senders blow through; DKIM keys need rotating; a careless p=reject published too early will silently bin your invoices, newsletters and password resets. DMARC Engine handles the awkward bits for you: it flattens and keeps your SPF record under the lookup limit, manages DKIM selectors and rotation, hosts MTA-STS and TLS reporting so mail is delivered over enforced TLS, and serves your BIMI record and logo so your brand mark can show in supporting inboxes. Most importantly, it ingests the RUA aggregate reports mailbox providers send back, identifies every service sending on your behalf (your CRM, helpdesk, finance tool, marketing platform and so on), and only recommends moving to quarantine or reject once those sources are authenticated and passing. You get emailed monitoring so you are told about a new sending source or an authentication failure rather than discovering it when a customer complains.
Who is it for? Any organisation that sends email from its own domain and wants to stop others spoofing it. That includes:
- Small businesses and agencies that send from Google Workspace or Microsoft 365 and want protection without hiring a deliverability specialist.
- E-commerce, SaaS and finance teams whose transactional mail (receipts, alerts, resets) must land reliably and must not be impersonated in phishing attacks.
- IT and security teams who need to satisfy supplier security questionnaires, cyber-insurance requirements or the bulk-sender rules now enforced by Google and Yahoo, which require a valid DMARC policy.
- Anyone who has tried to set up DMARC themselves, got stuck at the report stage, and has been parked at
p=nonefor months without ever reaching enforcement.
If you just want to check where you stand today, you do not need an account. The free diagnostic tools will tell you in seconds what is published and what is missing: the DMARC checker, SPF checker, DKIM checker, MTA-STS checker and BIMI checker, plus a DMARC report analyzer for reading aggregate files you already receive. When you are ready for someone to actually run the rollout for you, that is what the hosted products and the dashboard at app.dmarcengine.com do. For a plain-language primer on the standards themselves, see the glossary and the requirements overview.