How it works
From monitoring to reject — guided.
DMARC-IT automates the tedious work and removes the guesswork. You add a domain, we collect and enrich the reports, and the recommendation engine tells you exactly when it’s safe to tighten.
In five steps
- 01
Add your domain
For domains with a connected DNS integration we automatically publish the required RFC 7489 authorisation and a starting policy. Otherwise you get the DMARC record ready to copy.
p=none; rua=mailto:tok+…@reports.dmarc-it.be - 02
Reports flow in
Your rua address points to our EU edge. Daily DMARC reports are received, parsed (parsedmarc) and enriched with reverse-DNS, ASN, country and blocklist checks.
- 03
Every source is recognised
We identify each sending source — Microsoft 365, Google Workspace, SendGrid, your own server — and classify them approved, pending or blocked. New sources get an automatic suggestion.
- 04
The recommendation decides
The engine reasons per source, never on a total. It tells you precisely whether it’s safe to tighten — and if not, which sources block it and exactly what to fix (missing SPF vs DKIM).
- 05
Advance to reject
Once every approved source aligns reliably, you climb none → quarantine → reject — in one click or straight through your DNS integration, while we keep monitoring for regression.
Why this is different
Per-source, not per pass rate
A total percentage misleads. We classify each source separately and reason over that — so you never break a legitimate sender or miss a spoofer.
Verification is automated
RFC 7489 requires the reporting domain to authorise the rua provider, or major receivers send nothing. We handle that automatically at domain creation — no days without data.
EU-hosted, truly isolated
All data on Belgian/European servers, with Row-Level Security at the database level: every reseller and organisation sees only its own data — guaranteed.