How DMARC monitoring works

When your domain publishes a DMARC record with a rua address, every major mailbox provider — Gmail, Microsoft, Yahoo and thousands more — sends a daily XML report describing every server that sent email claiming to be you: how many messages, from which IPs, and whether they passed SPF and DKIM. Those reports are the raw truth about your domain. They are also unreadable gzip XML, which is why most companies never look at them.

What DMARCDECK does with them

1 — Collect. You add one DNS record; the reports flow to us. Nothing touches your mail flow — DMARC reporting is passive by design, so there is zero deliverability risk in monitoring.

2 — Classify. Every source IP is identified and geolocated, then classified: Authorized (your real mail systems), Forwarder (mailing lists and relays that break SPF but are harmless), or Threat (unauthenticated senders using your name). The moment a new Threat appears you get an email with the IP, country and network owner.

3 — Enforce. Monitoring alone stops nothing — the policy does. The enforcement autopilot scores your readiness and hands you the exact DNS record for each step: p=nonep=quarantinep=reject, timed so forwarders and slow senders are accounted for and no legitimate mail is lost. At p=reject, receiving servers refuse spoofed mail outright.

4 — Report. A weekly plain-language summary, a one-click executive PDF for management, CSV export for your IT team, and a live protection badge you can embed on your site.

Try it on your domain

The free checker audits your SPF, DKIM and DMARC in 10 seconds — including the SPF 10-lookup limit most tools miss. The 30-day trial includes everything above, no card required. Wondering how we compare? DMARC providers compared →

DMARCDECK is built and operated by LBCLOUDS, LLC · info@lbclouds.com
Home · Compare providers · DMARC in Lebanon · How it works