Domains stay at monitoring while the reports still show legitimate senders failing. When only forgeries are failing, moving to reject is one approval. We never make that change on a schedule.
The scan needs no account. Plans start at 12 €/mo with a 14-day trial.
Enforcement itself is one DNS value. Everything difficult about DMARC is the work before it: finding every service that sends as you, and knowing which of them would break.
Aggregate reports arrive as XML full of IP addresses. Each one is resolved to the service behind it, so the question "who is this?" already has an answer next to it.
Each policy stage shows the share of your traffic that would still pass under it. You move when the number says it is safe, with the figure in front of you rather than in a report you have to go and read.
The record lives in our zone, so changing policy is a click rather than a TXT edit at your registrar. It keeps resolving whether or not our application is running.