DMARC · SPF · DKIM — decision logic, not a dashboard
Enforce
without guessing.
DMARC-IT reads every sending source separately and tells you exactly when it’s safe to move from p=none to p=reject — with the blockers you need to fix first.
No credit card · setup < 5 min · cancel monthly
The policy only advances when every source is safe.
01 — 03 · decision logic“94% pass” tells you nothing. That failing 6% is either spoofing you want to block, or a legitimate sender that enforcement would break. Same number, opposite advice. That’s why we reason per source — never on the total.
Observe
We collect reports and classify every source as approved, pending or blocked.
Tighten
As soon as every approved source is ≥98% aligned over a ≥7-day window.
Enforce
Full protection — no newly approved source in the last 7 days.
Every source gets a name, a status and a fix.
per-source analysisNo impenetrable IP list. We recognise the sender, show SPF and DKIM alignment, and say exactly what to fix — or that it’s spoofing.
| Source | SPF | DKIM | Status | Action |
|---|---|---|---|---|
Microsoft 365 outbound · exchange online | 99.2% | 99.1% | approved | none — ready |
SendGrid transactional | 97.8% | 71.4% | pending | set up DKIM selector → |
Unknown sender 203.0.113.9 · no rDNS | 2.1% | 0.0% | blocked | likely spoofing — block |