Skip to content

Biz-Ai-DMARC

Product

Biz-Ai-DMARC

See every server that sends email as your domain, whether receivers trust it, and what to fix before you tell them to reject the rest.

A sealed envelope protected by a translucent shield

Resources

Guides and free tools

Guides

Free tools

No account needed, and both run entirely in your browser.

Email security basics

What DMARC is

Email was designed without any check on the From address. Anyone can send a message that claims to come from your domain, and to the recipient it looks exactly like yours. That is how most invoice fraud, fake password resets and “urgent request from the CEO” phishing works.

Three DNS records close that gap. SPF and DKIM let a receiving mail server verify a message, and DMARC (Domain-based Message Authentication, Reporting and Conformance) connects those checks to the address your recipients actually see, tells receivers what to do when a message fails, and asks them to send you a report of everything they saw. All three are open IETF standards: see where each one is defined.

At a glance

  • SPF: which servers may send for you. One TXT record on the domain.
  • DKIM: a signature on every message. One public key per sending service.
  • DMARC: the policy and the reports. One TXT record at _dmarc.
  • Cost to publish: nothing. All three are DNS records you already control.

The three records

How SPF, DKIM and DMARC fit together

  • SPF (Sender Policy Framework) is a list, published in DNS, of the servers allowed to send mail for your domain. The receiver checks the connecting server against it.
  • DKIM (DomainKeys Identified Mail) is a cryptographic signature added by the sending service. The receiver fetches your public key from DNS and confirms the message was not altered and really came from a holder of your key.
  • DMARC requires that at least one of those checks passes and lines up with the visible From domain. That match is called alignment, and it is what stops a spammer from passing SPF on their own domain while putting yours in the From line.
Three interlocking rings joined at a single point of light, standing for SPF, DKIM and DMARC

A DMARC record is one TXT record at _dmarc.yourdomain.com. A typical starting point:

v=DMARC1; p=none; rua=mailto:dmarc-reports@yourdomain.com
  • p is the policy: none (monitor only), quarantine (send failures to spam) or reject (refuse them).
  • rua is where receivers send daily aggregate reports. This is the address Biz-Ai-DMARC reads.
  • t=y is test mode: receivers apply the policy one step softer, so quarantine acts like none and reject like quarantine. It replaced the old pct tag in 2026.
  • sp sets a separate policy for subdomains, and np one for subdomains that do not exist at all. Attackers turn to both once the main domain is locked down.
  • Every tag, explained.

Why now

Why it matters now

Your name in someone else’s scam

Without an enforced DMARC policy, receivers have no instruction to refuse forged mail from your domain, so your customers and suppliers are the ones who get fooled.

Visibility

Most organizations do not know every service sending as their domain: the CRM, the billing system, the newsletter tool, the website contact form, a copier that emails scans. DMARC reports are the only complete list.

Deliverability

Since 2024 the largest mailbox providers require SPF, DKIM and a published DMARC record from anyone sending mail in volume. Mail that does not authenticate is increasingly filed as spam or refused outright, including your own invoices and quotes.

Reporting

The reports are the hard part

Envelopes on a conveyor flowing into a processing machine and coming out as charts

Once you publish a rua address, every major receiver sends a daily aggregate report: which IP addresses sent mail as your domain, how many messages, and whether each one passed SPF, DKIM and alignment. Some receivers also send forensic reports with details of individual failures.

They arrive as compressed XML attachments, one per receiver per day per domain. A small business with a few domains collects thousands of them a year. Nobody reads them by hand, so most domains that publish DMARC never move past p=none, and the protection never switches on. Biz-Ai-DMARC exists to turn that pile into answers.

The product

What Biz-Ai-DMARC does

Report intake

Reads the mailbox your rua address delivers to over IMAP, parses aggregate and forensic reports, and discards the duplicate copies receivers often send. Each organization connects its own mailboxes, with a built-in connection check. Report files can also be dropped in by hand and read as a table without importing them.

Alerts by email

A new sending source appears, compliance drops, DKIM failures spike, a domain’s published policy changes, reports stop arriving, or a forensic report comes in.

Weekly digest

One email per organization with volume, pass rate, quarantined and rejected messages per domain, and the week’s alerts.

Run by us

The app runs on our own infrastructure, access is by invitation, and public signup is switched off.

Sending sources

Every IP that sent as your domain, grouped into sources with message volume and SPF, DKIM and DMARC pass rates. Mark each source as verified, forwarder or threat, by IP range, hostname, SPF include or DKIM domain, and the rule applies to future reports automatically.

DNS tools

Checks a domain’s DMARC, SPF, DKIM, BIMI and MX records against best practice, including the SPF 10-lookup limit and DKIM key length, and keeps a snapshot so you can see when a record changed.

Many domains, many organizations

Each organization sees only its own domains, reports and mailboxes, with viewer, admin and owner roles. Reports are routed by the mailbox they arrived through, so one client’s data never lands in another client’s dashboard.

A laptop showing an analytics dashboard of bar, donut and line charts

Rollout

Rolling out DMARC without blocking your own mail

  1. Publish p=none with a rua address. Nothing is blocked yet; you are only collecting reports.
  2. Read the reports for two to four weeks, long enough to catch monthly billing runs and newsletters.
  3. Fix every legitimate source: add it to SPF or, better, have it sign with DKIM on your domain.
  4. Publish p=quarantine; t=y for a week or two, then remove t=y. Watch for anything legitimate that starts failing.
  5. Publish p=reject; t=y, then remove t=y, and set sp and np so subdomains are covered too.
  6. Keep reading the reports. New services get added, keys expire and vendors change their sending servers.
Steps rising toward a glass gate, standing for a gradual move to an enforced policy

The record at each stage

v=DMARC1; p=none; rua=mailto:...
v=DMARC1; p=quarantine; t=y; rua=mailto:...
v=DMARC1; p=quarantine; rua=mailto:...
v=DMARC1; p=reject; t=y; rua=mailto:...
v=DMARC1; p=reject; sp=reject; np=reject; rua=mailto:...

Test mode (t=y) replaced the old pct tag in RFC 9989 (2026). Receivers built before it ignore t and apply the full policy, so step up only when the reports show your legitimate mail passing.

Hygiene

SPF and DKIM hygiene

SPF

  • One SPF record per domain. Two records is an error, and receivers treat it as no SPF at all.
  • Stay under 10 DNS lookups. Each include: costs lookups, and past 10 SPF fails for everyone. Flattening the record into IP addresses fixes the count but breaks silently when a provider changes its servers.
  • ~all versus -all. Once DMARC is enforcing, a soft fail is enough; DMARC does the refusing.

DKIM

  • 2048-bit keys. Shorter keys are easier to break, and some receivers already treat them as weak.
  • One selector per sending service, so each can be rotated or revoked on its own.
  • Rotate about twice a year, and never leave the testing flag t=y in place.

Questions

Questions we hear

Will DMARC stop my own email?

Not at p=none, which only reports. It can if you jump straight to reject before every legitimate sender is authenticated. That is exactly what the reports and the rollout steps above prevent.

Do I need to change my email provider?

No. DMARC is a few DNS records and a mailbox to receive reports. It works with whatever mail service you already use.

What comes after enforcement?

BIMI shows your logo next to authenticated mail (most inboxes also require a mark certificate), and MTA-STS with TLS-RPT require encrypted delivery to your mail servers and report when it fails. Both build on an enforced DMARC policy.

How long until we can enforce?

Usually four to eight weeks for a small organization, most of it waiting for reports and chasing down the services nobody remembered were sending mail.

Who can see our reports?

Only the people you invite to your organization, plus us as the operator. Reports show sending IP addresses and message counts, not message contents.

How do we get access?

Access is by invitation. Send us a message with the domains you want to monitor, and we will set up your organization and walk you through the DNS changes.

Tell us what is not working

A 30-minute call, no pitch deck. We will tell you what we would do first, and whether we are the right people to do it.

Powered by Hostinger

This site is hosted on Hostinger. Some links here are affiliate links and may earn us a commission at no extra cost to you. We recommend only what we use ourselves or built ourselves. Read the full disclosure.