See every service sending email as your domain

We read the DMARC reports mailbox providers send and tell you which of your senders are failing — in Microsoft Teams, Discord, by email, or over the API. No dashboard to remember to check.

No credit card. No agent to install. Two DNS records.

SENDING SOURCES — LAST 7 DAYS SAMPLE DATA
Source Volume SPF DKIM Policy
mailchimp.com 89,442 PASS PASS PASS
sendgrid.net 24,101 PASS PASS PASS
smtp.example.com 9,812 PASS NONE PASS
198.51.100.42 1,477 FAIL FAIL REJECT

One unrecognised sender. That's the row you get told about.

PCI DSS v4.0 requirement 5.4.1 has required automated anti-phishing protection since 31 March 2025. PCI SSC names DMARC among the available techniques.

Source: PCI Security Standards Council, requirement 5.4.1

Google and Yahoo have required a DMARC record from bulk senders since February 2024.

Four things, done properly

Ingest the reports, work out who is sending, tell you when it changes, and get out of the way.

01

Report ingestion

XML, ZIP and GZIP reports are deduplicated, parsed and normalised into one consistent view.

02

Sender identification

Known sending ranges are resolved to the service behind them, while unknown sources remain visible for investigation.

03

Change alerts

New senders, authentication failures and DNS changes can trigger the notifications you choose.

04

Somewhere you already are

Microsoft Teams, Discord, email, webhook and API. The dashboard is optional.

From raw XML to a notification you can act on

Mailbox providers send aggregate reports as XML, often compressed and not always shaped in quite the same way. OnlyDMARC parses them, reconciles the same source across reports, and highlights changes that deserve attention.

  • XML, ZIP and GZIP report ingestion
  • Historical comparison across reporting periods
  • JSON export and API access for downstream processing
NEW SOURCE DETECTED — EXAMPLE.COM Unrecognised sending IP: 198.51.100.42 spf=fail dkim=fail disposition=quarantine
1,204 messages in last 6h

Five published requirements and guides that name DMARC

The scope differs. Each links to a fuller breakdown of who it applies to, with the primary sources.

PCI DSS v4.0

31 MAR 2025

Requirement 5.4.1 calls for automated anti-phishing mechanisms. PCI SSC includes DMARC in its examples rather than prescribing one single control.

Who this applies to →

Google bulk senders

NOV 2025

Senders delivering about 5,000 or more messages a day to personal Gmail accounts must use SPF, DKIM and DMARC. Enforcement ramped up again from November 2025.

Who this applies to →

Yahoo bulk senders

FEB 2024

Yahoo requires bulk senders to publish a valid DMARC policy and pass DMARC alignment, but does not publish a numeric bulk threshold.

Who this applies to →

Microsoft bulk senders

5 MAY 2025

Bulk senders to Outlook.com, Hotmail and Live consumer addresses must pass SPF, DKIM and aligned DMARC. Non-compliant high-volume mail is initially routed to Junk.

Who this applies to →

UK public-sector email

UPDATED MAR 2024

UK guidance says public-sector internet email domains must use DMARC, DKIM and SPF, enforce DMARC inbound, and review reporting.

Who this applies to →

Two DNS records and you're collecting data

Verify the domain with one TXT record, then add OnlyDMARC to the rua address in your DMARC record. Reports usually begin arriving after mailbox providers send their next aggregate report.

# verify domain ownership _onlydmarc-verify.example.com. IN TXT
"onlydmarc-verify=<token>"
# send aggregate reports to OnlyDMARC _dmarc.example.com. IN TXT
"v=DMARC1; p=none; rua=mailto:dmarc@onlydmarc.com"