Everything DMARCLoop does
DMARCLoop has one job: get your domain from "anyone can fake it" to "only you can send as it", without dropping a single real message along the way. Everything below is part of that job, and everything below is included on the free plan.
The free plan is limited to one domain and 1,000 messages a month. Paid plans raise those limits, but the features are identical.
-
See who's really sending as you, by name
DMARC reports arrive as raw numbers and IP addresses. On their own they're useless: “198.51.100.9 has been failing for nine days” leaves you with a research project. DMARCLoop does the research for you and says “SendGrid has been failing for nine days” instead, a name you recognise and can act on.
It works out who each sender is, groups the report data by service, and flags the ones that don't add up, like a sender with no proper return address, which legitimate bulk senders almost always have and impersonators often don't.
-
Get told when it's actually safe to start blocking
Tightening your DMARC policy is the moment things break if you rush it. DMARCLoop watches your real traffic over time and only gives you the green light once the numbers back it up: enough days of data, enough messages seen, a high enough pass rate. Monthly senders like payroll and invoicing don't show up in a week, so it deliberately waits long enough to catch them.
If something is still standing in the way, it doesn't just say “not yet”. It names the exact sender that's holding you back, so you know precisely what to fix. It also steps you up gradually rather than flipping straight to full blocking, because jumping to the deep end in one go is the single most common way a rollout goes wrong.
-
Catch the mail that looks fine now but breaks later
Some of your email passes today for a fragile reason that stops working the moment a message gets forwarded. It looks clean right up until you start blocking, and then it quietly fails. DMARCLoop spots this ahead of time and warns you which senders are relying on the fragile path, so you fix it before it bites rather than after.
-
Tell a real pattern from an attack at a glance
For any sender, DMARCLoop shows you a simple day-by-day view of its traffic. That pattern usually tells you what it is on sight: steady volume every weekday is one of your business apps, spikes on the 1st and the 15th are payroll or statements, one giant day and then nothing is a spam run using your name. You don't need to be an expert to read it.
-
Always know which domain needs attention today
If you look after more than one domain, DMARCLoop sorts them by what needs doing: domains still waiting to be verified first, then the ones not yet fully protected, then everything that's fine. A brand-new domain with no data yet is shown as “no reports yet”, never as a scary 0% that makes it look like your mail is broken when it's simply new.
-
Hear from us when something needs you, and only then
DMARCLoop emails you on exactly two things: when a domain is ready to be tightened (useful, not urgent), and when a domain is blocking real-looking mail right now (urgent, messages are being lost as you read this). It won't nag you with the same alert every morning, and alerts go only to the people who can actually act on them. Prefer Slack, Teams or a webhook? You can send alerts there too.
-
Daily monitoring that doesn't lie to you
DMARCLoop re-checks your domain's email records every day, with a faster sweep for domains you've just added so a change you make shows up in minutes, not tomorrow. There's a “Check now” button when you don't want to wait.
Two details most tools get wrong, and we don't: if a lookup fails on our end, we never wipe out your last known record and pretend you've published nothing, because a temporary glitch isn't a change on your part. And if your published record is actually broken, we tell you, instead of showing a reassuring green tick over a record no mail provider is honouring.
-
Setting up a domain is copy, paste, done
Add a domain and DMARCLoop hands you the exact records to publish, a verification record and your DMARC record, filled in and ready. Verification runs on the spot while you watch, so you get an answer in seconds, and the result is always clear: verified, not showing up yet (give DNS a few minutes), or a lookup problem on our side that isn't yours to fix. You'll never be left hunting for a record you already added correctly.
If your domain is already fully protected, setup keeps it that way. Adding a domain to DMARCLoop never changes how your mail is handled.
-
Already have a spreadsheet of domains? Import the lot
Switching from another tool, or setting up a client with dozens of domains? Upload a CSV and DMARCLoop imports them together. It does a dry run first and shows you exactly what it's about to do before it does anything, so there are no surprises.
-
Catch the inbound mail problem nobody gets warned about
There's a setting that forces incoming mail to your domain to use encryption. It's good security, but if it's misconfigured, senders quietly hold your mail back with no bounce and no error anywhere. Nothing in your normal email checks would ever show it. That silence is the whole reason this feature exists.
DMARCLoop watches this side of your domain too, grades each issue by how much mail it's actually costing you, and hands you a safe starting configuration built from your own mail servers, set up in a cautious “testing” mode first so you can't accidentally block your own incoming mail while you get it right.
-
Show an auditor you've done it, in one click
Buyers, insurers and auditors increasingly ask whether your email is protected. DMARCLoop turns your current setup into a one-click scorecard against the standards people actually get checked against, including the PCI security standard (which has required DMARC since March 2025) and the bulk-sender rules from Google, Yahoo and Microsoft. It's the document that gets you through a procurement questionnaire.
-
Regular reports, sent automatically
Set up a clean PDF or spreadsheet report to go out on a schedule, to you, your boss, or your client. Add a logo and it's a branded report you can hand straight to whoever needs to see that the domain is protected.
-
If our staff ever open your account, you see it
Any time someone on our side needs to look at your account to help, it's logged, with a written reason, a time limit, and, most importantly, a record you can read. Not an internal log you have to trust exists, but a page in your own dashboard showing when we looked, who looked, and why. It's the kind of transparency you'd want to be able to show your own customers.
-
Bring your team in, with the right level of access
Invite the rest of your team and give each person the access that fits: full control, day-to-day management, view-only, or limited to specific clients or domains. Everyone works in one account instead of sharing a single login.
-
Let us manage the tricky records for you
The email records behind all this can be fiddly to maintain by hand, and one of them has a hard limit that's the most common single cause of things breaking. With hosted records, you publish one small pointer once and DMARCLoop looks after the record from then on, including working around that limit automatically. No more manual DNS edits every time a sender changes.
Every feature above, at $0
One domain, 1,000 messages a month, and every feature on this page. No card, no trial clock, no stripped-down "starter" tier — start free and move up only when you need more domains or more volume.