Product
Biz-Ai-DMARC
See every server that sends email as your domain, whether receivers trust it, and what to fix before you tell them to reject the rest.

Resources
Guides and free tools
Guides
- DMARC record tags: every tag, what it does and what to set it to.
- DMARC alignment: why passing SPF or DKIM is not enough, and relaxed versus strict.
- SPF record syntax: mechanisms, qualifiers and the 10-lookup limit.
- DMARC glossary: the terms used in records and reports, in plain words.
- Email authentication standards: the IETF documents that define SPF, DKIM and DMARC, with links to the source.
Free tools
No account needed, and both run entirely in your browser.
- DMARC record generator: build a record for the current standard, ready to paste into DNS.
- DMARC report viewer: open an aggregate report file and read it as a table. Nothing is uploaded.
Email security basics
What DMARC is
Email was designed without any check on the From address. Anyone can send a message that claims to come from your domain, and to the recipient it looks exactly like yours. That is how most invoice fraud, fake password resets and “urgent request from the CEO” phishing works.
Three DNS records close that gap. SPF and DKIM let a receiving mail server verify a message, and DMARC (Domain-based Message Authentication, Reporting and Conformance) connects those checks to the address your recipients actually see, tells receivers what to do when a message fails, and asks them to send you a report of everything they saw. All three are open IETF standards: see where each one is defined.
At a glance
- SPF: which servers may send for you. One TXT record on the domain.
- DKIM: a signature on every message. One public key per sending service.
- DMARC: the policy and the reports. One TXT record at
_dmarc. - Cost to publish: nothing. All three are DNS records you already control.
The three records
How SPF, DKIM and DMARC fit together
- SPF (Sender Policy Framework) is a list, published in DNS, of the servers allowed to send mail for your domain. The receiver checks the connecting server against it.
- DKIM (DomainKeys Identified Mail) is a cryptographic signature added by the sending service. The receiver fetches your public key from DNS and confirms the message was not altered and really came from a holder of your key.
- DMARC requires that at least one of those checks passes and lines up with the visible From domain. That match is called alignment, and it is what stops a spammer from passing SPF on their own domain while putting yours in the From line.

A DMARC record is one TXT record at _dmarc.yourdomain.com. A typical starting point:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
pis the policy:none(monitor only),quarantine(send failures to spam) orreject(refuse them).ruais where receivers send daily aggregate reports. This is the address Biz-Ai-DMARC reads.t=yis test mode: receivers apply the policy one step softer, soquarantineacts likenoneandrejectlikequarantine. It replaced the oldpcttag in 2026.spsets a separate policy for subdomains, andnpone for subdomains that do not exist at all. Attackers turn to both once the main domain is locked down.- Every tag, explained.
Why now
Why it matters now
Your name in someone else’s scam
Without an enforced DMARC policy, receivers have no instruction to refuse forged mail from your domain, so your customers and suppliers are the ones who get fooled.
Visibility
Most organizations do not know every service sending as their domain: the CRM, the billing system, the newsletter tool, the website contact form, a copier that emails scans. DMARC reports are the only complete list.
Deliverability
Since 2024 the largest mailbox providers require SPF, DKIM and a published DMARC record from anyone sending mail in volume. Mail that does not authenticate is increasingly filed as spam or refused outright, including your own invoices and quotes.
Reporting
The reports are the hard part

Once you publish a rua address, every major receiver sends a daily aggregate report: which IP addresses sent mail as your domain, how many messages, and whether each one passed SPF, DKIM and alignment. Some receivers also send forensic reports with details of individual failures.
They arrive as compressed XML attachments, one per receiver per day per domain. A small business with a few domains collects thousands of them a year. Nobody reads them by hand, so most domains that publish DMARC never move past p=none, and the protection never switches on. Biz-Ai-DMARC exists to turn that pile into answers.
The product
What Biz-Ai-DMARC does
Report intake
Reads the mailbox your rua address delivers to over IMAP, parses aggregate and forensic reports, and discards the duplicate copies receivers often send. Each organization connects its own mailboxes, with a built-in connection check. Report files can also be dropped in by hand and read as a table without importing them.
Alerts by email
A new sending source appears, compliance drops, DKIM failures spike, a domain’s published policy changes, reports stop arriving, or a forensic report comes in.
Weekly digest
One email per organization with volume, pass rate, quarantined and rejected messages per domain, and the week’s alerts.
Run by us
The app runs on our own infrastructure, access is by invitation, and public signup is switched off.
Sending sources
Every IP that sent as your domain, grouped into sources with message volume and SPF, DKIM and DMARC pass rates. Mark each source as verified, forwarder or threat, by IP range, hostname, SPF include or DKIM domain, and the rule applies to future reports automatically.
DNS tools
Checks a domain’s DMARC, SPF, DKIM, BIMI and MX records against best practice, including the SPF 10-lookup limit and DKIM key length, and keeps a snapshot so you can see when a record changed.
Many domains, many organizations
Each organization sees only its own domains, reports and mailboxes, with viewer, admin and owner roles. Reports are routed by the mailbox they arrived through, so one client’s data never lands in another client’s dashboard.

Rollout
Rolling out DMARC without blocking your own mail
- Publish
p=nonewith aruaaddress. Nothing is blocked yet; you are only collecting reports. - Read the reports for two to four weeks, long enough to catch monthly billing runs and newsletters.
- Fix every legitimate source: add it to SPF or, better, have it sign with DKIM on your domain.
- Publish
p=quarantine; t=yfor a week or two, then removet=y. Watch for anything legitimate that starts failing. - Publish
p=reject; t=y, then removet=y, and setspandnpso subdomains are covered too. - Keep reading the reports. New services get added, keys expire and vendors change their sending servers.

The record at each stage
v=DMARC1; p=none; rua=mailto:...
v=DMARC1; p=quarantine; t=y; rua=mailto:...
v=DMARC1; p=quarantine; rua=mailto:...
v=DMARC1; p=reject; t=y; rua=mailto:...
v=DMARC1; p=reject; sp=reject; np=reject; rua=mailto:...
Test mode (t=y) replaced the old pct tag in RFC 9989 (2026). Receivers built before it ignore t and apply the full policy, so step up only when the reports show your legitimate mail passing.
Hygiene
SPF and DKIM hygiene
SPF
- One SPF record per domain. Two records is an error, and receivers treat it as no SPF at all.
- Stay under 10 DNS lookups. Each
include:costs lookups, and past 10 SPF fails for everyone. Flattening the record into IP addresses fixes the count but breaks silently when a provider changes its servers. ~allversus-all. Once DMARC is enforcing, a soft fail is enough; DMARC does the refusing.
DKIM
- 2048-bit keys. Shorter keys are easier to break, and some receivers already treat them as weak.
- One selector per sending service, so each can be rotated or revoked on its own.
- Rotate about twice a year, and never leave the testing flag
t=yin place.
Questions
Questions we hear
Will DMARC stop my own email?
Not at p=none, which only reports. It can if you jump straight to reject before every legitimate sender is authenticated. That is exactly what the reports and the rollout steps above prevent.
Do I need to change my email provider?
No. DMARC is a few DNS records and a mailbox to receive reports. It works with whatever mail service you already use.
What comes after enforcement?
BIMI shows your logo next to authenticated mail (most inboxes also require a mark certificate), and MTA-STS with TLS-RPT require encrypted delivery to your mail servers and report when it fails. Both build on an enforced DMARC policy.
How long until we can enforce?
Usually four to eight weeks for a small organization, most of it waiting for reports and chasing down the services nobody remembered were sending mail.
Who can see our reports?
Only the people you invite to your organization, plus us as the operator. Reports show sending IP addresses and message counts, not message contents.
How do we get access?
Access is by invitation. Send us a message with the domains you want to monitor, and we will set up your organization and walk you through the DNS changes.
Tell us what is not working
A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.