DMARC Engine
Home/Report & monitoring
Free report & monitoring

Get a free DMARC report, and keep watch

We will email you a full report on your domain's email authentication, and, if you like, re-check it every day and alert you the moment anything changes.

Enter your domain and email and we will send you a full report on its email authentication, covering DMARC, SPF, DKIM, MTA-STS, DNSSEC and BIMI, with a clear score out of 100 and exactly what to fix. Tick the box and we will also re-check it every day and email you only if something changes (a weakened DMARC policy, a broken SPF record, and so on).

We email the report to the address you enter and store the scan so you can view it online. Monitoring is opt-in and confirmed by email. See our privacy policy.

What the free report covers

The report is a full authentication audit, sent straight to your inbox and stored so you can open it online whenever you like. It checks every layer that decides whether your mail is trusted, and it tells you in plain English what is set up correctly and what is putting you at risk. There is nothing to install and no login required to read it.

DMARC

Whether a record exists, what policy it sets (p=none, quarantine or reject), whether reporting is switched on, and whether the policy actually protects you or just watches.

SPF

Whether the record is present and valid, how many of the 10 permitted DNS lookups it uses, and whether it is heading for a permerror that silently fails every send.

DKIM

Whether signing keys are published for the selectors we can see, whether the key length is strong enough, and whether the signing domain can align with your From address.

MTA-STS & TLS-RPT

Whether you enforce TLS on inbound mail so it cannot be downgraded to plaintext, and whether you collect TLS reporting to spot delivery problems.

DNSSEC

Whether your zone is signed so the answers to DNS queries cannot be tampered with in transit, which underpins the trust in everything else.

BIMI

Whether your verified logo can appear next to your mail in supporting inboxes, and what you still need (enforcement and, for some providers, a VMC) to qualify.

Every finding rolls up into a single score out of 100 and a letter grade, so you can see at a glance whether your domain is in good shape or quietly exposed. Each item comes with the specific change that would fix it, in the order that matters, so the report is a to-do list rather than a wall of red crosses.

Why a single grade helps. Authentication has a lot of moving parts, and it is easy for one broken piece to hide behind five working ones. A clear grade turns "is our email set up properly?" into a number you can track, share with a colleague and improve.

Why a one-off check is not enough

A report tells you where your domain stands today. The problem is that "today" does not last. Email setups drift constantly, usually without anyone meaning to change anything, and a configuration that was clean last quarter can be quietly leaking by this one. The damage rarely announces itself, which is exactly why it is worth watching for.

Three things change underneath you, all of them silent.

  • Drift. Someone edits a DNS record, a provider rotates its sending IPs, a key expires, a record gets truncated during a migration. Each small change can break SPF or DKIM for a sending source without any warning, and the mail keeps sending while it fails authentication.
  • New senders. A team signs up for a new invoicing tool, a marketing platform or a help desk and starts sending as your domain. If that source is not authenticated and aligned, it either lands in spam or, once you are enforced, gets blocked outright. New senders appear far more often than most organisations realise.
  • A weakened policy. The most dangerous change of all: a DMARC policy that drops from p=reject back to p=none, or a record that disappears entirely. The moment that happens, the door to spoofing reopens and nobody gets an error. Your mail still flows, so nothing looks wrong, while forgers can once again send fake invoices from your domain.
The quiet reopening. A domain can spend months at p=reject, fully protected, and then a single careless DNS edit drops it back to p=none. From the outside everything looks normal. Without monitoring, you would only find out when a customer pays a fraudulent invoice.

How change alerts work

Tick the box on the form and, once you confirm by email, we re-check your domain every day. We take a snapshot of your full authentication posture and compare it with the last good one. If nothing has changed, you hear nothing from us: no daily digest to ignore, no noise. We only email you when something is actually different, and the alert says plainly what changed, why it matters and what to do about it.

  1. You opt in. Monitoring is off unless you ask for it. We send a confirmation link to the address you entered, and monitoring only starts once you click it.
  2. We re-scan daily. Each day we run the same checks as your report and record the result.
  3. We compare against the baseline. The new snapshot is measured against your previous one so we can tell a genuine change from normal day-to-day query variation.
  4. We alert on real changes only. When a meaningful difference appears, you get one clear email. When nothing changes, your inbox stays quiet.

What triggers an alert

Alerts fire on the changes that actually move your risk, not on cosmetic noise. Typical triggers include:

  • Your DMARC policy weakening, for example p=reject or p=quarantine dropping to p=none.
  • Your DMARC, SPF or DKIM record disappearing or becoming malformed.
  • SPF crossing the 10-lookup limit and tipping into permerror.
  • A DKIM selector going missing or a key being removed or shortened.
  • MTA-STS or DNSSEC being switched off or misconfigured.
  • Your overall score or grade dropping by a meaningful margin.
Signal, not spam. The point of monitoring is to surface the handful of changes that matter and stay silent the rest of the time. An alert from us means something genuinely needs your attention.

How monitoring fits the path to p=reject

Getting to an enforced p=reject policy is not a one-time switch you flip and forget. It is a staged rollout: you start at p=none with reporting on, find every legitimate sender, fix authentication and alignment for each one, then raise the policy in steps until spoofers are blocked and no real mail is. Monitoring is what keeps that work from unravelling.

While you climb towards enforcement, daily checks confirm that each change holds and that no new unauthenticated sender has appeared to undo your progress. Once you reach p=reject, monitoring is what keeps you there. It catches the accidental policy downgrade, the expired key and the new tool the marketing team added last week, before any of them turns into spam-foldered invoices or a reopened spoofing gap. Enforcement protects your domain; monitoring protects your enforcement.

If you would rather not run the staged rollout yourself, our team does the whole path for you. We host your DMARC, SPF, DKIM, MTA-STS and BIMI, take you safely from p=none to p=reject with no email outage, and keep watching afterwards. The free report and monitoring are a no-obligation way to see what that work would involve.

Privacy: we email a report, that is all

This is a deliberately low-commitment tool, and we treat it that way.

  • We only query public DNS. The report reads records that anyone on the internet can look up. We do not need access to your mail, your servers or your DNS provider to produce it.
  • Monitoring is opt-in and confirmed. We never start watching a domain on a whim. You tick the box, we send a confirmation link, and monitoring begins only after you click it.
  • One-click unsubscribe. Every alert email carries a one-click unsubscribe link. Stop monitoring whenever you like, no account or login needed.
  • We use your email to send the report. We email the report to the address you provide and store the scan so you can view it online. Full detail is in our privacy policy.

Frequently asked questions

Is the report really free?

Yes. The report and the optional daily monitoring cost nothing. They exist so you can see exactly where your domain stands before deciding whether you want help fixing it. There is no card required and no trial that quietly converts.

Do I have to turn on monitoring to get the report?

No. The report is sent whether or not you tick the monitoring box. Monitoring is entirely optional and opt-in, and you confirm it by email before it starts.

How often will you email me?

For the report, once. For monitoring, only when something actually changes. If your domain stays the same, you will not hear from us. We do not send daily digests or marketing blasts off the back of a scan.

Will monitoring change anything on my domain?

No. Monitoring is read-only. We look up your public DNS records and compare them day to day. We make no changes to your records, your mail flow or anything else unless you separately ask us to manage your authentication for you.

How is this different from full DMARC reporting?

The free report checks the configuration of your records: are they present, valid, aligned and enforced. Full DMARC aggregate reporting (the rua= data) shows you which sources are actually sending mail as your domain and whether each passes. The two work together: this report gets your records right, and our analytics and reporting show you the live traffic once you are set up.

I already have DMARC. Is monitoring still worth it?

Especially then. A domain at p=reject has the most to lose from a silent downgrade or a broken record, because it has real protection that can quietly disappear. Monitoring is the simplest way to make sure the protection you set up is still there tomorrow.

See where your domain stands, then keep it there

Start with the report. It takes a few seconds, it costs nothing, and it tells you in plain terms whether your email is protected or exposed. Turn on monitoring if you want us to keep watch, and if you would like the whole path to p=reject handled for you, we are one short call away.

Written and reviewed by the DMARC Engine team · Last reviewed June 2026

See where your domain stands today

Run a free DMARC scan, then let us take you to enforced p=reject with no email outage.