Powerful aggregation. Smart alerts. Not "Yet Another Dashboard". Get clear visibility into who's sending email on your behalf — without forcing your team into another bloated web interface.
DMARC monitoring doesn't need to be complex or expensive. OnlyDMARC gives you the insights that matter, delivered how you work.
Automatic ingestion of RUA reports (XML, ZIP, GZIP) from all major providers. Deduplication, normalisation, and historical retention built in.
Configurable alerts for new sending sources, failure spikes, DNS record changes, and policy drift — delivered via Slack, Teams, email, or webhook.
REST API with webhook push support. Model Context Protocol (MCP) compatibility for AI-assisted analysis. Pipe DMARC data directly into your SIEM or SOC pipeline.
Structured insight into every sending IP: HELO/EHLO identities, envelope-from domains, header-from alignment, SPF & DKIM signing results, and DMARC disposition.
Continuous DNS validation checks across SPF, DKIM, and DMARC records. Instant alerts on syntax errors, lookup limit breaches, and policy changes.
Clean, lightweight web interface designed for quick investigation — not daily dashboard-watching. You're here to check something, not to live here.
You don't want to log into yet another SaaS app. Most teams already use Slack, Teams, SIEM platforms, and ticketing systems. OnlyDMARC plugs into the systems you're already using.
Token-authenticated API for programmatic access to your DMARC data. OpenAPI spec included.
Real-time HTTP push on events: new sources, failures, policy changes, DNS drift.
Model Context Protocol support for AI-assisted DMARC investigation and triage.
Slack, Microsoft Teams, and email alert delivery. Configure per-domain, per-event-type.
PCI DSS v4.0 made DMARC mandatory for any organisation processing cardholder data from 31 March 2025. The EU's DORA regulation, UK government policy since 2016, and Google & Yahoo sender requirements have all moved DMARC from "best practice" to baseline requirement.
The question isn't whether you can afford DMARC monitoring. It's whether you can afford to enforce a policy without it.
Learn why it mattersAnti-phishing mechanisms including DMARC, SPF, and DKIM became mandatory on 31 March 2025 for any entity processing cardholder data.
Fully applicable since January 2025, DMARC is increasingly treated as a baseline ICT resilience indicator for financial entities and their technology suppliers.
Bulk senders must have DMARC at p=none or stronger. Enforcement protects deliverability across major mailbox providers.
Add your DMARC RUA address, point your DNS record at us, and start seeing data. No agents, no complex setup, no consultants required.