DMARC monitoring that shows who sends as your domain.

Unspam collects the DMARC aggregate reports mailbox providers send about your domain, turns them into named sending sources, and tells you when your policy is ready for p=quarantine or p=reject.

Why most domains never get past p=none.

Reports arrive as XML nobody reads

Once your record has a rua address, receivers like Gmail, Outlook and Yahoo send you compressed XML files every day. Each one lists IP addresses and raw results, and none of them says which of your tools sent the mail.

Nobody has the full list of senders

Marketing platforms, billing systems, help desks and CRMs all send as your domain. Tighten the policy before every one of them aligns, and that tool’s mail starts going to spam or bouncing.

Spoofing hides in the same failures

Mail that fails DMARC is either a legitimate tool you forgot to authenticate or someone using your domain without permission. As raw IP addresses, the two look exactly alike.

Enforcement feels like a gamble

At p=none, anyone can still send as your domain. Move to p=reject too early and you block your own mail. Without evidence that it is safe, the policy stays where it is for years.

Your DMARC data, readable at a glance.

Compliance and alignment for every domain.

The domain list covers the last 30 days: messages reported, the share that passed DMARC, SPF and DKIM alignment, and the policy each record publishes. Open a domain for its daily volume timeline, with the policy changes receivers reported marked on it.

Every sending source, named and sorted.

Reported IP addresses are grouped into sources and categorized as an email service provider, your own infrastructure, a forwarder, or suspected spoofing, each marked compliant, partially failing, failing or unauthorized. Open a source to see why its mail fails and how to fix it.

Built to get you to an enforced policy.

Policy readiness, checked for you

For each domain, Unspam checks whether you can move to p=quarantine or p=reject and lists what stands in the way: too few days of data, compliance below the threshold, a failing source, or traffic nobody has reviewed yet.

One DNS record, verified automatically

We generate the exact record to publish. If you already have one, you get that record with our reporting address added, so your policy stays as it is. Unspam checks your DNS on its own and verifies the record the moment it appears.

Priced per domain, first one free

DMARC monitoring is part of the Custom plan at $6 per domain per month. Your first domain is included at no charge, you can add up to 500, and annual billing takes 15% off.

How it works.

01

Add your domain

Enter the domain in DMARC Reports. Unspam generates the record to publish, or adds our reporting address to the record you already have.

02

Publish one DNS record

Paste the value at your DNS provider. Your mail flow does not change, and neither does your current policy.

03

Verification happens on its own

Unspam checks your DNS and verifies the domain as soon as the record is live. If our reporting address is later removed from the record, the domain says so.

04

Read your first reports

Mailbox providers usually send their first aggregate reports 24 to 48 hours after verification. From then on, every report is parsed, attributed to a source and added to your charts.

A few common workflows.

Reading reports is the means. These are the jobs teams use DMARC monitoring for.

  • Build an inventory of every sender

    Before you touch the policy, use the sources list as the inventory: every platform that sends as your domain, how much it sends, and whether it aligns.

  • Move from p=none to p=reject safely

    Work through the readiness blockers one at a time, mark the sources you recognize as legitimate, and tighten the policy when nothing stands in the way.

  • See who is spoofing your domain

    Sources flagged as suspected spoofing or unauthorized show mail that uses your domain without passing DMARC, and how much of it receivers saw.

  • Confirm a DKIM or SPF fix held

    After you enable DKIM on a new tool or correct an SPF include, watch that source move from failing to compliant as the next days of reports come in.

  • Check a migration before the old path goes dark

    Switching email providers or adding a sending subdomain? The daily timeline shows whether mail on the new path aligns while the old one is still running.

  • Watch client and brand domains side by side

    Agencies and multi-brand teams add every domain to one account and compare compliance, alignment and policy across all of them in a single list.

Frequently Asked Questions

What DMARC monitoring is, what it costs, and how Unspam handles your reports.

What is DMARC monitoring?

DMARC monitoring is collecting and reading the aggregate reports that mailbox providers send about mail using your domain. The rua tag in your DMARC record tells receivers where to send them. A monitoring service parses those XML files, groups the results by sending source, and shows which mail passes DMARC, which fails, and why. It is how you move from p=none to an enforced policy without blocking your own mail. To inspect the record itself, use the free DMARC checker.

How much does DMARC monitoring cost?

DMARC monitoring is part of the Custom plan. Each domain costs $6 per month, your first domain is included free, you can monitor up to 500 domains, and annual billing takes 15% off. The Free plan does not include it. Build a plan on the pricing page.

Can I read DMARC reports for free?

For a one-off look, yes. The free DMARC report analyzer reads a single aggregate report. Monitoring does that for every report as it arrives, attributes the traffic to sources, keeps the history, and tracks whether your domain is ready for a stricter policy.

Do I need to change my DMARC policy or DNS?

Only the reporting address changes. With no DMARC record yet, Unspam generates one for you. With an existing record, you get the same record with our address added, so your policy and any other report recipients stay as they are. Some receivers honor only the first two rua addresses, so keep ours among them. To write a record from scratch, try the DMARC record generator.

How long until the first reports arrive?

Mailbox providers send aggregate reports on their own schedule, usually once a day. Most send the first one 24 to 48 hours after your record goes live, and the latest day or two of data can still be filling in.

What happens to my data if I remove a domain?

Monitoring for that domain stops immediately, and every report received for it, including the archived report files, is permanently deleted.

How is this different from Deliverability Monitoring?

They answer different questions. DMARC monitoring reads what receivers report about authentication for all mail that uses your domain. Deliverability Monitoring sends a test message on a schedule and checks whether it lands in the inbox or in spam at each provider. DMARC controls who can send as your domain; placement tests confirm that the mail you send reaches the inbox.

Can I see the raw DMARC reports?

Yes. Behind the charts, every aggregate report received is listed reporter by reporter. Open one to see each record’s source IP, what the receiver did with the mail, the aligned DKIM and SPF verdicts, and the raw authentication results they came from. The badge beside each reporter shows how far its data can be trusted.

See who is sending as your domain.

Add a domain, publish one DNS record, and read your first DMARC reports within about two days.