When your domain publishes a DMARC record with a rua address,
every major mailbox provider — Gmail, Microsoft, Yahoo and thousands more — sends
a daily XML report describing every server that sent email claiming to be
you: how many messages, from which IPs, and whether they passed SPF and DKIM.
Those reports are the raw truth about your domain. They are also unreadable gzip
XML, which is why most companies never look at them.
1 — Collect. You add one DNS record; the reports flow to us. Nothing touches your mail flow — DMARC reporting is passive by design, so there is zero deliverability risk in monitoring.
2 — Classify. Every source IP is identified and geolocated, then classified: Authorized (your real mail systems), Forwarder (mailing lists and relays that break SPF but are harmless), or Threat (unauthenticated senders using your name). The moment a new Threat appears you get an email with the IP, country and network owner.
3 — Enforce. Monitoring alone stops nothing — the policy does.
The enforcement autopilot scores your readiness and hands you the exact DNS
record for each step: p=none → p=quarantine →
p=reject, timed so forwarders and slow senders are accounted for and
no legitimate mail is lost. At p=reject, receiving servers refuse
spoofed mail outright.
4 — Report. A weekly plain-language summary, a one-click executive PDF for management, CSV export for your IT team, and a live protection badge you can embed on your site.
The free checker audits your SPF, DKIM and DMARC in 10 seconds — including the SPF 10-lookup limit most tools miss. The 30-day trial includes everything above, no card required. Wondering how we compare? DMARC providers compared →
DMARCDECK is built and operated by LBCLOUDS, LLC · info@lbclouds.com
Home · Compare providers · DMARC in Lebanon · How it works