Report ingestion
XML, ZIP and GZIP reports are deduplicated, parsed and normalised into one consistent view.
We read the DMARC reports mailbox providers send and tell you which of your senders are failing — in Microsoft Teams, Discord, by email, or over the API. No dashboard to remember to check.
No credit card. No agent to install. Two DNS records.
One unrecognised sender. That's the row you get told about.
Ingest the reports, work out who is sending, tell you when it changes, and get out of the way.
XML, ZIP and GZIP reports are deduplicated, parsed and normalised into one consistent view.
Known sending ranges are resolved to the service behind them, while unknown sources remain visible for investigation.
New senders, authentication failures and DNS changes can trigger the notifications you choose.
Microsoft Teams, Discord, email, webhook and API. The dashboard is optional.
Mailbox providers send aggregate reports as XML, often compressed and not always shaped in quite the same way. OnlyDMARC parses them, reconciles the same source across reports, and highlights changes that deserve attention.
spf=fail dkim=fail disposition=quarantine
1,204 messages in last 6hThe scope differs. Each links to a fuller breakdown of who it applies to, with the primary sources.
Requirement 5.4.1 calls for automated anti-phishing mechanisms. PCI SSC includes DMARC in its examples rather than prescribing one single control.
Who this applies to →Senders delivering about 5,000 or more messages a day to personal Gmail accounts must use SPF, DKIM and DMARC. Enforcement ramped up again from November 2025.
Who this applies to →Yahoo requires bulk senders to publish a valid DMARC policy and pass DMARC alignment, but does not publish a numeric bulk threshold.
Who this applies to →Bulk senders to Outlook.com, Hotmail and Live consumer addresses must pass SPF, DKIM and aligned DMARC. Non-compliant high-volume mail is initially routed to Junk.
Who this applies to →UK guidance says public-sector internet email domains must use DMARC, DKIM and SPF, enforce DMARC inbound, and review reporting.
Who this applies to →Verify the domain with one TXT record, then add OnlyDMARC to the rua address in your DMARC record. Reports usually begin arriving after mailbox providers send their next aggregate report.
_onlydmarc-verify.example.com. IN TXT
"onlydmarc-verify=<token>"
# send aggregate reports to OnlyDMARC
_dmarc.example.com. IN TXT
"v=DMARC1; p=none; rua=mailto:dmarc@onlydmarc.com"