One-click DNS remediation: preview, apply, revert

Once your DNS provider is connected to DMARCER, you can publish recommended record changes straight from the domain window, with a clear before-and-after preview first. Every change is logged so you can always see what changed and put it back if you need to.

Published 22 Jul 2026 1

When your DNS provider is connected to DMARCER, you can publish recommended record changes straight from the domain window, and you always get a full before-and-after preview before anything is saved. DMARCER reads your live DNS settings from the provider, combines your proposed record with what is already there, lets you check the exact result, then saves it back through the provider when you approve it. Every change is logged, so you can always see what changed and restore the previous record whenever you need to.

What one-click remediation does

  • Reads the current record live from your connected provider, so the preview matches exactly what will be saved.
  • Combines your proposed record with what is already published. For DMARC, this keeps your existing rua= and ruf= reporting addresses rather than replacing them.
  • Shows a colour-coded before-and-after comparison: added rows in green, removed rows in red, changed rows in amber, and unchanged rows in neutral.
  • Saves the record back through the provider only when you click Apply changes, then automatically rechecks the domain so your dashboard reflects the new status without waiting for the next routine check.
  • Records every change in the domain's History tab, with the before value, the after value, where the change came from and who made it.

The colour-coded before-and-after preview is used for DMARC records (the _dmarc TXT record) and SPF records (the v=spf1 TXT record on your main domain). The same publish-through-your-provider approach also covers MTA-STS and TLS-RPT records, turning DNSSEC on or off, and the occasional verification TXT records DMARCER needs to add, although those are applied directly rather than shown as a colour-coded comparison.

Before you start

  • DNS integration is included on some plans. If the publish options are not showing, your plan may not include it yet, and the preview shows the message "DNS Integration is not on your current plan." Just get in touch and we will help.
  • The domain needs to be linked to a connected DNS zone, under Integrations and then Manage zones & links. If a domain is not linked, you will see copy-and-paste instructions instead of an Apply button.
  • The integration needs to be active. If it is paused, the publish is declined and the reason is shown.
  • You need a role that can manage domains. View-only users do not see the Apply controls.
  • Your provider needs to support saving changes automatically. Where a provider cannot make a particular change for you, DMARCER shows the record to copy rather than an Apply button.

Previewing and applying a change

  1. Open the domain from the Domains grid and go to the right tab: the DMARC window's Create/Update tab for DMARC, or the SPF window's Builder tab for SPF.
  2. Build or accept the recommended record. The DMARC window's Enforcement Journey tab also offers an Apply button for the next recommended step.
  3. Click Publish. DMARCER reads your live DNS settings and opens the review dialog, titled "Publish DMARC record" or "Publish SPF record" for your domain.
  4. Review the comparison. The dialog names the integration the change will go through and shows the full combined record that will be saved.
  5. If nothing needs to change, the dialog tells you no change is required and there is nothing to apply.
  6. Click Apply changes to save the record. A spinner appears while your provider is updated, then a message confirms it, and a recheck runs a couple of seconds later to refresh your dashboard.

What each option and safeguard means

  • DMARC merge: your existing rua= and ruf= reporting addresses are kept, and only the highlighted fields change. That is why the dialog shows a field-by-field comparison rather than a single overwrite, so you can see exactly which addresses stay and which are added.
  • SPF safety checks: DMARCER will not publish an SPF record that needs more than 10 direct lookups (going over this limit causes a permanent error that makes receivers treat your SPF as broken), or one that is not a valid SPF record (it must contain v=spf1). These checks cannot be turned off. A record with no senders that ends in -all is allowed, but flagged with a warning, since that is the right record for a parked or brand-protection domain that sends no email.
  • Removing a known sender: if a change would remove a recognised sending service, you are asked to type the domain name to confirm before Apply changes becomes available. This is a deliberate safeguard against accidentally cutting off a live sender.
  • Lookup headroom: the SPF builder shows the count of direct lookups. Each service can add further lookups of its own behind the scenes, so it is worth leaving some room under 10.
  • SPF Flattening lock: if the domain is using SPF Flattening (Activating, Live or Reverting), publishing from the Builder is blocked so it cannot overwrite the flattened line. While in that state, manage SPF from the Flattening tab.

Reverting a change

Every publish is recorded in the History tab of the DMARC window, with the exact before and after record, where the change came from and who made it. To put a record back, reopen the relevant window, set the record to the previous value (the History tab's Before column shows it), and publish again through the same preview-and-apply steps. Because every save is freshly combined with your live DNS settings, this is safe to do at any time.

  • DMARC and SPF: publish the previous record again using the same Publish then Apply changes steps; the History tab shows the value to restore.
  • MTA-STS: use Revert to testing on the MTA-STS window for a quick rollback out of enforce mode.
  • DNSSEC: use Disable DNSSEC. Because this carries more risk, it asks you to type the domain name to confirm.

Common pitfalls

  • "Domain isn't linked to any integration": link the zone under Integrations, then Manage zones & links, before trying to publish.
  • "Integration is suspended": reactivate the integration, or add its sign-in details again, then try once more.
  • "Provider rejected the credentials": update the saved sign-in details for the integration.
  • "Provider rate limit hit": wait a moment and try again. Providers limit how many changes are allowed in a short space of time.
  • Status not updating straight away: the automatic recheck waits a couple of seconds for the change to spread across DNS. If the record was only just saved, give it another routine check before worrying.
  • Browser tab left open a while: there is no need to worry. DMARCER re-reads and re-combines your live DNS settings at the moment you click Apply changes, so it will not quietly lose a change someone else made in the meantime.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles