The DMARCER REST API lets you read and manage your tenancy's data programmatically. It covers domains, customers, and Radar brand protection, so you can wire DMARCER into your own tooling, onboarding, or PSA.
Base URL
https://api.dmarcer.net
All endpoints are versioned under /v1.
Create an API key
API access is part of your subscription. In the app, go to Integrations, then API and create a key. You will see the full token once, so store it securely. Only a hash is kept.
A token looks like:
dmk_live_<prefix>_<secret>
Authenticate
Send the token as a bearer credential on every request:
Authorization: Bearer dmk_live_<prefix>_<secret>
Example:
curl https://api.dmarcer.net/v1/domains \ -H "Authorization: Bearer dmk_live_..."
Scopes
Each key is granted a set of scopes. Requests are rejected if the key lacks the scope for the operation:
customers:readandcustomers:writedomains:read,domains:writeanddomains:scanradar:readandradar:write
Read and write are separate grants, and scanning (which does work and may be billable) is its own grant, never implied by read.
Tenant vs customer keys
- A tenant-scoped key sees the whole tenancy, and can narrow with
?customerId=. - A customer-scoped key only ever sees and acts on that one customer's data. This is enforced on the server, not just by convention.
Rate limits and errors
Requests are rate-limited per tenancy. Errors return a JSON body:
{ "error": "invalid", "message": "status must be open, investigating, accepted, dismissed, suppressed or all." }
Common statuses: 401 (bad or expired key), 403 (missing scope), 404 (not found or out of scope), 429 (rate limited).
See the per-area guides, for example Radar API, for the specific endpoints.