Skip to main content
ValidPeak LogoValidPeak
DMARC Monitoring
DMARC MONITORING

DMARC Monitoring — See Who'sSending Email From Your Domain, Right Now

Protect your domain from spoofing and phishing in real time. Monitor SPF, DKIM, and DMARC compliance across every sending source — with alerts in under 60 seconds.

Real-time alerts in under 60 seconds
SPF & DKIM alignment tracking
SOC 2 Certified
No credit card required
10K+Domains monitored
<60sAlert response time
200+ISPs & mailbox providers tracked
UNDERSTANDING DMARC

The Three Pillars of Email Authentication

SPF, DKIM, and DMARC work together to verify email authenticity and protect your domain from unauthorized use.

01
SPFSender Policy Framework

Verifies that the sending server's IP address is authorized to send email on behalf of your domain. Prevents unauthorized servers from spoofing your address.

IP → DNS Lookup → Authorize
02
DKIMDomainKeys Identified Mail

Adds a cryptographic signature to outgoing emails, allowing recipients to verify the message hasn't been altered in transit and truly originates from your domain.

Sign → Transmit → Verify Key
03
DMARCDomain-based Message Authentication

Ties SPF and DKIM together with a policy that tells receiving servers how to handle messages that fail authentication. Provides reporting on all email activity.

SPF + DKIM → Policy → Report
LIVE MONITORING

Your DMARC Compliance at a Glance

Real-time visibility into your email authentication status across all sending sources.

85%Pass Rate
Pass85%
SPF-Only10%
Fail5%
Total Reports24,847
Sending Sources142
Authorized Senders98
Threats Blocked1,247
DMARC POLICYReject
SPF ALIGNMENT97.2%
DKIM ALIGNMENT99.1%
DEEP ANALYSIS

Granular Protocol-Level Insights

Dive deep into SPF, DKIM, and DMARC results with detailed breakdowns and actionable intelligence.

SPF Results
Pass72%
Fail8%
SoftFail15%
Neutral5%
DKIM Results
Pass91%
Fail9%
Aggregate Report Processing

Automatically processes RUA aggregate reports from all receiving mail servers, providing clear visualizations of your authentication landscape.

Forensic Report Analysis

Detailed failure analysis from RUF forensic reports, pinpointing exactly which messages failed and why for rapid remediation.

DNS Record Validation

Continuously validates your SPF, DKIM, and DMARC DNS records, alerting you to misconfigurations or unauthorized changes instantly.

Subdomain Monitoring

Automatically discovers and monitors authentication status across all your subdomains, ensuring complete protection coverage.

THREAT DETECTION

Stop Spoofing Before It Damages Your Brand

Identify unauthorized senders, detect phishing attempts, and get real-time alerts when someone tries to impersonate your domain. Protect your brand and your customers.

Live Threat Feed
Live

Domain Spoofing

unknown-ip.xyz attempting to send as yourcompany.com

2 min ago

SPF Failure

Mail from 185.220.101.45 failed SPF check

8 min ago

Phishing Attempt

Unauthorized sender impersonating support@yourcompany.com

23 min ago

New Source Detected

mailchimp-123.com sending as yourcompany.com — verify

1h ago
Domain Spoofing

Unauthorized senders impersonating your domain to send fraudulent emails

1,247 blocked this month
Phishing Attacks

Malicious actors using your domain in phishing campaigns targeting your customers

98.6% detection rate
Unauthorized Senders

Third-party services sending emails from your domain without proper authentication

142 sources identified
REPORTING & ALERTS

Automated Reports &
Intelligent Alerts

Get detailed DMARC reports delivered to your inbox and receive instant alerts when authentication failures spike or new threats emerge.

Automated Reports

Schedule comprehensive DMARC reports delivered directly to your team.

Daily, weekly, or monthly aggregate reports
Executive summaries with compliance scores
Custom branded reports for stakeholders
CSV and PDF export formats
Smart Alerts

Configure intelligent alerts based on thresholds, anomalies, and threat patterns.

Instant alerts on new unauthorized senders
SPF/DKIM failure rate threshold notifications
Slack, email, and webhook integrations
Custom alert rules per domain
COMPLIANCE JOURNEY

From Vulnerable to
Fully Protected

ValidPeak guides you through every step of DMARC implementation, from initial monitoring to full enforcement with p=reject.

1
p=none
Monitor

Start collecting DMARC data without affecting mail flow. Identify all legitimate sending sources.

2
SPF + DKIM
Authenticate

Configure SPF and DKIM for all authorized senders. Fix alignment issues before enforcement.

3
p=quarantine
Quarantine

Move to quarantine policy. Suspicious emails are sent to spam while you monitor impact.

4
p=reject
Enforce

Full DMARC enforcement. Unauthorized emails are rejected, your domain is fully protected.

Before ValidPeak
No visibility into email authentication
Domain vulnerable to spoofing attacks
Manual XML report parsing
Compliance gaps with no audit trail
After ValidPeak
Complete DMARC visibility in real-time
Full p=reject enforcement blocking threats
Automated reports with actionable insights
SOC 2 & GDPR compliant with full audit trail
QUICK SETUP

How to set up DMARC Monitoring in 3 steps

From zero to full visibility in under 5 minutes of setup — no engineering required.

01

Create your account & add your domain

2 minutes

Sign up for a free ValidPeak account and add the domain you want to monitor. ValidPeak automatically scans for your existing DMARC record — if there isn't one, it generates the correct record for you to add to your DNS.

02

Add the reporting address to your DMARC record

1 minute

Update your DMARC DNS record to include ValidPeak's reporting address. This tells ISPs where to send aggregate reports — DMARC reports will start arriving within 24 hours.

Add to your DMARC TXT record:
v=DMARC1; p=none; rua=mailto:dmarc@reports.validpeak.com

Already have an rua= address? Add ValidPeak's address separated by a comma — you can have multiple recipients.

03

Your dashboard populates in 24–48 hours

Automatic

Once the first DMARC reports arrive, your dashboard fills with real data. You'll see:

Every IP address and sending source using your domain
SPF and DKIM pass/fail rates per source
Volume trends: how many emails were sent and from where
Your current DMARC policy and compliance percentage
Any unauthorized or suspicious senders flagged immediately

What to do before enabling DMARC monitoring — SPF and DKIM first

DMARC monitoring only shows meaningful data if SPF and DKIM are properly configured first. Without them, every email will fail authentication — and you won't be able to distinguish legitimate sends from spoofing attempts. Use the free tools below to verify both before you start:

Check SPF →Check DMARC →
PRICING

Start free. Scale when you need it.

No credit card required. Free plan is permanent — not a trial.

Free
€0forever
Start free
Domains monitored1
DMARC report parsing
Sending source discovery
SPF & DKIM alignment
Blacklist checksDaily
Alert response time24 hrs
Email validation credits/mo200
Campaign Intelligence
API access
Starter
€28/mo, billed annually
Start Starter
Domains monitored5
DMARC report parsing
Sending source discovery
SPF & DKIM alignment
Blacklist checksDaily
Alert response time< 4 hrs
Email validation credits/mo1,500
Campaign Intelligence
API access
Most popular
Pro
€142/mo, billed annually
Domains monitoredUnlimited
DMARC report parsing
Sending source discovery
SPF & DKIM alignment
Blacklist checksReal-time
Alert response time< 60 sec
Email validation credits/mo20,000
Campaign Intelligence
API access
Enterprise
Custom
Contact sales
Domains monitoredUnlimited
DMARC report parsing
Sending source discovery
SPF & DKIM alignment
Blacklist checksReal-time
Alert response time< 60 sec
Email validation credits/moCustom
Campaign Intelligence
API access
FAQ

Frequently asked questions

Everything you need to know before getting started with DMARC monitoring.

The short answer: without DMARC monitoring, you don't — and that's the problem. Most businesses find out their domain has been spoofed when a customer replies to a phishing email they never sent, or when their own emails start landing in spam because ISPs have flagged the domain as suspicious.

ValidPeak shows you every IP address and sending source that's used your domain in the last 24 hours — your own ESP, your transactional email service, your CRM, and any unauthorized source that's impersonating you. The first time most customers run this check, they find at least one sender they don't recognize. It's not always malicious (sometimes it's a forgotten third-party tool), but you need to see it to deal with it.

No — and this is the most important thing to understand before you start. Setting up DMARC monitoring with a p=none policy is completely invisible to your recipients. It tells ISPs "watch what's happening but don't do anything yet." Your campaigns, your transactional emails, your sequences — nothing changes.

The moment deliverability is at risk is if you jump straight to p=reject without first mapping out all your legitimate sending sources. ValidPeak's compliance dashboard shows you your SPF and DKIM pass rates for every sender before you touch the policy. The standard path is: p=none (monitor) → p=quarantine (test) → p=reject (full protection). ValidPeak guides you through each step with a readiness indicator so you know when it's actually safe to move forward.

Real-time blacklist monitoring fires in under 60 seconds if your domain appears on any of the 200+ blacklists ValidPeak tracks. For DMARC-specific threats — unauthorized senders, policy failures — the detection happens as DMARC aggregate reports arrive from ISPs, typically within a few hours of the sending activity.

The alert tells you the specific IP, the volume of emails sent, which ISPs received them, and whether SPF or DKIM failed. You're not just told "something's wrong" — you're told exactly who, where, and what to do next.

This is the right instinct — moving to p=reject too quickly is one of the most common ways companies accidentally destroy their own deliverability. The risk is always the same: a legitimate sending source (a marketing platform, a helpdesk tool, a regional office ESP) isn't properly authenticated, and suddenly those emails get blocked.

The safe path has three phases. First, run on p=none for at least 2–4 weeks and let ValidPeak map every source sending from your domain. Second, make sure SPF and DKIM pass for every legitimate source. Third, move to p=quarantine and monitor spam folder placement for a week before going to p=reject. ValidPeak's compliance journey tracks your readiness score across all three phases and tells you when each transition is safe.

Think of it as layers. SPF is a list of IP addresses you've approved to send email for your domain — ISPs check if the sending server is on that list. DKIM is a cryptographic signature baked into the email headers — ISPs verify the email wasn't tampered with in transit. DMARC is the layer on top that ties both together and tells ISPs what to do when either check fails: let it through, quarantine it, or reject it.

You need all three because SPF and DKIM alone don't protect you from spoofing the From: address — they only check infrastructure. DMARC adds alignment: it verifies that the domain in the From: field actually matches the domain that passed SPF or DKIM. Without that alignment check, someone can pass SPF while still spoofing your brand name. ValidPeak checks SPF alignment and DKIM alignment separately so you can see exactly which sources are fully aligned and which aren't.

The free plan is permanent and genuinely functional for a single domain. You get real DMARC report parsing, full sending source discovery, SPF and DKIM alignment tracking, daily blacklist checks, and 200 email validation credits per month. For a small business or solo operator with one domain and no urgency around real-time alerts, it covers the core use case.

Where the paid plans matter: if you need alerts in under 60 seconds instead of the next day (Starter: under 4 hours, Pro: under 60 seconds), if you're managing 5+ domains (Starter covers 5, Pro is unlimited), or if you need Campaign Intelligence. The free plan has no time limit and no credit card requirement — just volume and speed limits.

Postmark DMARC Digests is free and sends you a weekly email digest — useful for basic visibility, but it's read-only. It shows you data without recommendations, without real-time alerts, and without any connection to how your domain's authentication health affects your sending. dmarcian is more powerful but built primarily for enterprise compliance teams, with pricing to match.

ValidPeak's key difference is Campaign Intelligence — the only platform that connects your DMARC compliance score to a pre-send campaign risk engine. If your DMARC compliance rate dropped in the last 48 hours, Campaign Intelligence surfaces that as a risk factor before you send, not after a campaign underperforms. It's one platform for authentication health, blacklist monitoring, domain warmup, and campaign readiness — not four separate tools.

DMARC aggregate reports start arriving from major ISPs (Gmail, Outlook, Yahoo) within 24–48 hours of updating your DNS record. Within the first week, you'll typically have enough data to see your full sender map — every IP and service sending on behalf of your domain, with pass/fail rates for each.

The setup itself takes under 5 minutes: add your domain in ValidPeak, it scans for your existing DMARC record (or generates one), then you add rua=mailto:dmarc@reports.validpeak.com to your DNS record. From that point it's automatic — ValidPeak parses the incoming XML reports and translates them into plain-language findings. No log files, no XML parsing.

Campaign Intelligence is ValidPeak's pre-send scoring engine. Before you send a campaign, it calculates a 0–100 risk score based on five signals: DMARC compliance rate, warmup progress, blacklist health, inbox placement history, and domain stability over time. It tells you whether it's safe to send, and if not, exactly what to fix first.

The DMARC connection is direct: if your DMARC compliance rate drops — because an unauthorized sender appeared, or because you misconfigured SPF for a new tool — that shows up as a risk factor in Campaign Intelligence before your next send. Most platforms don't connect these two. You'd have to check your DMARC dashboard separately, notice the drop, figure out it's affecting deliverability, and then decide whether to delay the campaign. ValidPeak does that automatically.

DMARC monitoring helps you understand why you ended up on a blacklist and prevents it from happening again — but the delisting itself still requires fixing the root cause.

Here's how it works in practice: ValidPeak alerts you in under 60 seconds when your domain appears on any of the 200+ blacklists it tracks. The alert includes which blacklist flagged you, the likely reason (unauthorized sender, spam complaint spike, policy mismatch), and the step-by-step delisting process for that specific blacklist. If the root cause was someone spoofing your domain — which DMARC monitoring would have caught earlier — moving to p=reject closes that vector permanently. If the cause was your own sending practices, ValidPeak's compliance dashboard shows you exactly which sources are generating failures so you can fix authentication before submitting a delisting request.

Protect Your Domain
From Email Threats

Start monitoring your DMARC compliance in minutes. Get full visibility into who is sending emails from your domain.

View Live Demo
SOC 2 Compliant
GDPR Ready
5-Minute Setup
No Credit Card Required