Reach p=reject without losing real mail

Domains stay at monitoring while the reports still show legitimate senders failing. When only forgeries are failing, moving to reject is one approval. We never make that change on a schedule.

The scan needs no account. Plans start at 12 €/mo with a 14-day trial.

DMARC policy_dmarc TXT
p=nonep=quarantinep=reject
v=DMARC1;p=none;p=quarantine;p=reject;rua=mailto:…@ingest.sentradmarc.com
Your mail
0
delivered
Forgeries
0
delivered

The hard part is knowing when it is safe

Enforcement itself is one DNS value. Everything difficult about DMARC is the work before it: finding every service that sends as you, and knowing which of them would break.

Every sender, named

Aggregate reports arrive as XML full of IP addresses. Each one is resolved to the service behind it, so the question "who is this?" already has an answer next to it.

Readiness at the moment you decide

Each policy stage shows the share of your traffic that would still pass under it. You move when the number says it is safe, with the figure in front of you rather than in a report you have to go and read.

One approval, no DNS edit

The record lives in our zone, so changing policy is a click rather than a TXT edit at your registrar. It keeps resolving whether or not our application is running.