From sign-up to p=reject
The whole rollout, in the order you will do it. Each article covers one step: what to click, what to publish, and how to tell it worked.
The rollout at a glance
- Day 0 Set up Create an account, add your domain and publish two TXT records. Nothing about how your mail is handled changes.
- Day 1–2 First report Mail receivers send aggregate reports once a day. The first usually lands within 48 hours.
- Day 14 Quarantine review At least two weeks of reports covers your weekly senders. If they all pass, test p=quarantine.
- Day 30 Enforce quarantine Thirty days covers the monthly senders — invoicing, payroll, statements. Then drop t=y and enforce quarantine.
- Month 3–6 Reject With quarantine enforcing cleanly and every sender aligned, test and then enforce p=reject.
Getting started
Create an account and choose where to start.
- 01 Create your account Sign up with your work email, confirm the address, and know who else should be in the account before they sign up on their own.
- 02 Choose a plan Start free with no card, or pick a paid plan and add billing details. What the limits mean, and what happens when you change plan later.
- 03 Set up two-factor authentication Protect your DMARCLoop sign-in with a code from an authenticator app, save your backup codes, and know what to do if you lose your phone.
Your first domain
Add a domain, publish two DNS records and wait for the first report.
- 04 Add your first domain Which domain to start with, what to type, and what DMARCLoop sets up the moment you add it.
- 05 Publish the DNS records The two TXT records DMARCLoop needs, where to add them (with steps for Cloudflare, GoDaddy and Microsoft 365), and how to hand the job to IT.
- 06 Verify the domain Run the ownership check once the records are published, what each result means, and how the domain page shows your DMARC record being picked up.
- 07 Get your first report When the first DMARC report arrives, how to tell setup is finished, and what the domain page shows you on day one.
Moving to enforcement
Work through your senders, then tighten the policy when the evidence says it is safe.
- 08 Identify your sending sources Between the first report and day 14, work through the servers sending as your domain — authorise the ones that are yours, and leave the rest to the policy.
- 09 The 14-day review: moving to p=quarantine When the policy advisor recommends testing p=quarantine (14 days of reports) and enforcing it (30 days), what it checks, and how to make the change.
- 10 The 30-day review: moving to p=reject Reject waits for 30 days of reports and a month at enforced quarantine. What the advisor checks, and how to take the final step safely.
- 11 Staying at p=reject Enforcement isn't the end of monitoring: the alerts DMARCLoop sends, the weekly digest, and what to do when you add a new sending service.
- 12 Hosted records Point three CNAMEs at DMARCLoop and manage your DMARC policy, DKIM keys and SPF from the dashboard, with no DNS change for each enforcement step.
- 13 SPF and the ten-lookup limit Why an SPF record stops working as you add senders, how DMARCLoop tells you, and what hosted SPF flattening does and refuses to do.
Reports
What each report shows, failure reports, and sending reports to people who don't log in.
- 14 Read the DMARC report What the numbers on Reports → DMARC and the domain page's alignment view mean, and why a high pass rate is not a low spoofing rate.
- 15 Failure reports What DMARC failure (ruf) reports collect, why they hold other people's data, and how to turn them on, set their retention and turn them off.
- 16 MTA-STS and TLS reports How DMARCLoop monitors inbound TLS — the MTA-STS policy, the optional TLS-RPT record and the reports it brings — and the order to publish them in.
- 17 Compliance reports How Reports → Compliance assesses each domain against the ASD ISM, PCI DSS v4.0, the bulk-sender rules and NIST SP 800-177, and how to download the PDF.
- 18 Saved and scheduled reports Email a PDF or CSV DMARC report weekly or monthly to people who don't log in, keep copies to download later, and put your logo on them.
Your account
People and roles, sign-in security, notifications, usage, billing and settings.
- 19 Invite people and set their roles Invite colleagues from Account → People, choose a role and which clients they can see, and manage invitations and removals.
- 20 Notifications and alerts Choose which alert emails reach you, turn the weekly digest on or off, and send alerts to Slack, Microsoft Teams or a webhook.
- 21 The email log Account → Emails lists every email DMARCLoop sent about your account, who it went to and whether it arrived, so you can check without asking support.
- 22 Check your usage Account → Usage shows your active domains and compliant messages against your plan, what each one counts, and what happens if you go over.
- 23 Manage billing and invoices Account → Billing shows your plan, changes or cancels it, and keeps every invoice, payment, credit and refund. Who can use it, and what each change does.
- 24 Account settings Account → Settings holds your account name and invoice details, and links to single sign-on, alert channels, hosted records and scheduled reports.
- 25 The access log Account → Access log records every time DMARCLoop staff open your account, look up one of your domains or change something, with the reason they gave.
For MSPs
Clients, bulk import, reporting to your customers, and statements.
- 26 Clients, domains and who sees what How an MSP account is organised into clients, how domains belong to them and move between them, and what a member limited to one client sees.
- 27 Import domains in bulk Add up to a thousand domains at once from a pasted list or a CSV, see exactly what each row would do first, and get one records email per client.
- 28 Reports for your clients Schedule a monthly or weekly DMARC report for each client with your logo on it, what your customer receives, and which names they see in DNS.
- 29 Usage and monthly statements How an MSP account is measured and billed, the per-client figures to re-bill against, and reviewing each month's draft statement before it's invoiced.
Troubleshooting
When something has not happened that should have.
Looking for background rather than steps? The FAQ explains alignment, DMARCbis and sending on behalf of other domains, and the free tools check any domain's records without an account.