build
Free tools
More than 40 checkers and generators covering DMARC, SPF, DKIM, BIMI, MTA-STS and the underlying DNS. Paste a domain and read back exactly what is published: which records exist, whether they parse, how many SPF lookups you are using, what selectors are signing, and where a record is missing or malformed.
Use this when you want a fast, no-signup answer to "what does my domain actually say today" or you need to generate a correct record to publish. Start at the free tools, or get a fuller picture by email through the report and monitoring page.
menu_book
Setup guides
Step-by-step DNS instructions for publishing each record correctly the first time, written so you can follow them in your registrar or DNS host without guessing. They cover the record syntax, where it goes, common copy-paste mistakes, and how to confirm it has taken effect.
Use this when a tool has told you what is wrong and you are ready to make the change yourself. Open the setup guides.
menu_book
Glossary
Plain-English definitions of every email-authentication term, from alignment and selectors to p=reject and aggregate reports. Each entry is short, jargon-free, and linked to a tool so you can check the term against your own domain straight away.
Use this when a report, an audit, or a colleague uses a word you are not certain about. Browse the glossary.
verified_user
Provider requirements
What Google, Yahoo and Microsoft actually require from bulk senders, and what PCI DSS 4.0 expects from organisations handling card data. This is the practical detail behind the deadlines: thresholds, the difference between a recommendation and a hard rule, and what happens to your mail if you ignore them.
Use this when you need to know whether you are obligated to do this, and by when. Read the provider requirements.
route
How enforcement works
The four-step path from p=none to an enforced p=reject without an email outage: audit what is sending, align SPF and DKIM, move the policy up in stages, and monitor so it stays that way. This is the method, explained so you can see why each step comes in that order.
Use this when you understand the pieces and want to see how they fit into a safe rollout. Start with step one, audit.
balance
Compare options
An honest comparison of free tools, doing it yourself, and a done-for-you hosted service. It lays out what each approach costs in money and time, where each one tends to break, and which suits a single domain versus a large or fast-changing estate.
Use this when you have decided to act and are choosing how to do it. Read the comparison.
description
Why it matters
The risk explainers connect the technical gap to the real harm: how an unprotected domain turns into invoice and payment fraud, why poor authentication quietly erodes deliverability, and how it leads to a failed audit. Concrete examples, not scare stories.
Use this when you need to explain to a colleague or a budget holder why this is worth doing. Start with invoice fraud.
article
Blog, docs and knowledge base
The blog covers practical topics around reaching and keeping enforcement. The documentation explains how to set up and run DMARC Engine across all your domains. The knowledge base gives short, direct answers to common setup and troubleshooting questions.
Use this when you want depth on a specific topic, or you are running the platform and need a precise how-to or a quick fix.