Moving to enforcement Step 12 of 30
Hosted records
Point three CNAMEs at DMARCLoop and manage your DMARC policy, DKIM keys and SPF from the dashboard, with no DNS change for each enforcement step.
Updated
Everything else in DMARCLoop watches your DNS. Hosted records are the one feature that answers it: you point three names at us once, and from then on your DMARC policy, DKIM keys and SPF are published from the dashboard.
Hosted records are optional and not included on every plan; the pricing page lists what each plan includes. On a plan without them, the hosted records page says Not included in your plan.
When it’s worth it
- Moving through the policy ladder. Each step in the 14-day and 30-day reviews is a change to your DMARC record. With hosted records it’s a change on the hosted DMARC screen instead of a ticket to whoever edits your DNS.
- Sending services that change their addresses. We keep SPF up to date for the services you use, including staying under SPF’s ten-lookup limit.
- DKIM key rotation, without a DNS change each time.
Setting it up
Hosted records are offered once the domain is verified — we won’t publish a DMARC policy for a domain until we know you control it.
- On the domain page, under Hosted records, choose Set them up.
- Choose Set up hosted records. We set the records up first; nothing changes yet.
- Publish the three CNAMEs the page lists, in place of your current records at those names. You can do them one at a time — each name keeps answering from your own DNS until you point it at us.
From then on, the hosted page is where the policy lives: Policy, Subdomains, Non-existent subdomains and Testing mode (t=y) are fields there, saved with Save policy, and SPF is managed under Host SPF for this domain.
Who can change what
| On the hosted records page | Needs |
|---|---|
| Set up hosted records, the DMARC policy, and Turn off hosted records | Admin or above |
| The SPF settings: Host SPF for this domain, The record to flatten and How the record ends | Analyst or above |
Anyone else sees what is published without the form. For the policy, the page says Changing the policy needs an administrator — it decides what receivers do with this domain’s mail.; for SPF, Changing the SPF settings needs the analyst role or higher.; and before hosting is set up, Setting up hosted records needs an administrator.
If your existing DMARC record sends reports to another service as well, those
addresses are carried over to the hosted record. While
failure reports are
on for the domain, the hosted record also carries DMARCLoop’s ruf address,
added and removed for you. The DMARC section of the hosted page says which:
Failure reports are on for this domain, so the record we publish also
carries the ruf=mailto: address, or Failure reports are off for this
domain, so the record we publish has no ruf tag.
With hosted SPF, one record stays yours: the SPF record on the domain itself,
which the page shows under And this one record on the domain itself. It
includes your _spf name, so adding or removing a sender never means editing
it. How it ends is the exception: hosted SPF keeps your record’s ending
(-all, ~all or ?all) unless you choose another under How the record
ends, and receivers act on the ending of the record on your domain — so a
changed ending means publishing your domain’s own SPF record again. Until
you do, the old ending is the one in force. The line under the record says
whether what we last saw on your domain matches; see
SPF and the ten-lookup limit.
What it changes
- We become part of your mail path. We answer DNS for those three names. If our nameservers stopped answering, your SPF would stop resolving and receivers would treat your record as if it weren’t there. That’s the trade for not having to touch DNS again, and it’s why we tell you if a CNAME stops pointing at us (the Hosted DNS delegation broken alert).
- You can stop at any time. Turning hosting off leaves the records published while you put your own back, so it isn’t an outage.
Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.