Getting started with the DMARCER API

Authenticate, understand scopes and key types, and make your first call to the DMARCER REST API.

Published 25 Aug 2026 43

The DMARCER REST API lets you read and manage your tenancy's data programmatically. It covers domains, customers, and Radar brand protection, so you can wire DMARCER into your own tooling, onboarding, or PSA.

Base URL

https://api.dmarcer.net

All endpoints are versioned under /v1.

Create an API key

API access is part of your subscription. In the app, go to Integrations, then API and create a key. You will see the full token once, so store it securely. Only a hash is kept.

A token looks like:

dmk_live_<prefix>_<secret>

Authenticate

Send the token as a bearer credential on every request:

Authorization: Bearer dmk_live_<prefix>_<secret>

Example:

curl https://api.dmarcer.net/v1/domains \ -H "Authorization: Bearer dmk_live_..."

Scopes

Each key is granted a set of scopes. Requests are rejected if the key lacks the scope for the operation:

  • customers:read and customers:write
  • domains:read, domains:write and domains:scan
  • radar:read and radar:write

Read and write are separate grants, and scanning (which does work and may be billable) is its own grant, never implied by read.

Tenant vs customer keys

  • A tenant-scoped key sees the whole tenancy, and can narrow with ?customerId=.
  • A customer-scoped key only ever sees and acts on that one customer's data. This is enforced on the server, not just by convention.

Rate limits and errors

Requests are rate-limited per tenancy. Errors return a JSON body:

{ "error": "invalid", "message": "status must be open, investigating, accepted, dismissed, suppressed or all." }

Common statuses: 401 (bad or expired key), 403 (missing scope), 404 (not found or out of scope), 429 (rate limited).

See the per-area guides, for example Radar API, for the specific endpoints.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment