DMARC monitoring & enforcement

Know who's sending email as your domain. Then stop the ones who shouldn't.

Scammers can send email that looks like it came from you — to your customers, staff and suppliers. DMARCLoop shows you exactly who is sending in your name, sorts the real senders from the fakes, and walks you to full enforcement without losing a single real message.

SPF, DKIM, DMARC, MX, MTA-STS and TLS-RPT, graded A–F. No account needed.

Free plan · no card · every feature included

Reads the reports from the mail everyone already sends

  • Google Workspace
  • Microsoft 365
  • Mailchimp
  • SendGrid
  • Salesforce
  • Zendesk
The problem

Anyone can put your name on an email

Email was built to be trusting. Nothing stops a stranger from putting your company's name in the "From" line and sending it to whoever they like — that's how most phishing and invoice fraud works. DMARC locks this down, and Google, Yahoo and Microsoft now expect you to have it if you send in any volume.

The catch: turn it on carelessly and you don't just block the fakes. You block your own invoices, booking confirmations and payroll notices, and no one tells you it happened. That's the problem DMARCLoop is built to solve.

Why DMARCLoop

We find your real senders first, then help you block the rest

  • See every sender

    The big mail providers report on every message using your domain. DMARCLoop reads those dense files for you and turns them into a plain list: your CRM, your payroll provider, your newsletter tool — and the one failing for nine days straight that you don't recognise.

  • Know when it's safe to tighten

    Move from p=none to p=reject too early and you cut off a real sender you forgot about. DMARCLoop watches the traffic and only tells you to tighten once the evidence says it's safe — and names the exact sender if something is still in the way.

  • Never break your own mail

    The part most tools get wrong. DMARCLoop won't recommend a change that would drop legitimate messages, and if a real sender ever starts failing you get an email the same morning — before your customers notice, not after.

See everything the platform does
  • 9 free tools, no account needed
  • RFC 9989 DMARCbis — the current spec, not obsolete 7489
  • 1,000 messages a month on the free plan
  • Same-day alerts when a real sender starts failing
How the rollout works

From p=none to p=reject, without the guesswork

  1. 1

    Point your reports at DMARCLoop

    Publish a DMARC record at p=none with our rua address. Takes one DNS change; we walk you through it. Reports start arriving within a day.

  2. 2

    Watch your real traffic build

    We sort every source into people you recognise and people you don't, and track alignment over time — so you can see, not guess, what enforcement would block.

  3. 3

    Tighten to p=reject, safely

    When the evidence says every legitimate sender is covered, DMARCLoop tells you it's time — and keeps watching so nothing quietly breaks afterwards.

Pricing

Every feature is on the free plan

No stripped-down "starter". The free plan is the whole product, capped at one domain and 1,000 messages a month. You only move up when you need more domains or more volume — same tool, bigger limits.

Free

$0 No card required.

One domain, 1,000 messages a month, every feature.

Start free
Most popular

Enforce

From $279 USD / month

Ten domains and the volume for a full rollout across a business.

Start free
Compare all plans
Get started

Lock down your domain this week

Start free, publish one DNS record, and watch your real senders appear. No card, no sales call, and you can be at p=reject sooner than you think.