PSA ticketing: turning alerts into tickets

How DMARCER can raise a ticket in your PSA when it spots a domain-security problem, keep that ticket up to date, and close it again once things are back to normal. Covers the two places you set this up and how a domain finds the right customer.

Published 3 Jul 2026 22

DMARCER can raise a ticket in your PSA whenever it spots a domain-security problem, then keep that ticket in step with what is happening: updating it as the situation changes and closing it again once things are back to normal. That way email-authentication issues land in the same queue your team already works from, with the right priority and against the right customer, instead of sitting in a separate inbox.

There are two places to set this up: an account-wide choice of which kinds of alert should push to your PSA, and a per-integration Alerts tab that decides how the tickets are created. You need both in place before tickets will start to flow.

What it does

When an alert fires for a domain, DMARCER checks two things: whether that kind of alert is set to push to your PSA, and whether the affected domain can be matched to a customer in your PSA. If both are true, it opens a ticket and remembers it, so it can keep that ticket up to date over time.

  • Open: the first time a problem is detected, DMARCER creates a ticket with the status, priority, team and ticket type you have chosen.
  • Update: if the same problem comes back at a higher (or lower) severity, or with new detail, DMARCER adds a note to the existing ticket instead of opening a duplicate, and adjusts the priority when the severity changes.
  • Self-heal: once the problem clears, DMARCER can move the ticket to a status you choose (for example Resolved) and add a closing note.

If you have more than one PSA integration connected, a ticked alert opens a ticket in all of them. We do this on purpose to keep the setup simple, so there is no need to choose tick boxes for each PSA separately.

Step one: choose which alerts push to your PSA

Go to Alerts then Settings. Once you have at least one active PSA integration, an extra PSA column appears in the Alert types table (it stays hidden until then, so the page is not cluttered). Each row is one kind of alert, with small labels showing how often it is checked and which channels are switched on.

Click Configure on the alert you want. In the panel that opens, you can tick In-app, Email and PSA independently. The PSA tick box reads "PSA: open a ticket; self-heal closes it". Tick it and click Save. Each change saves on its own, so you can work through the list one alert at a time.

  • This choice applies across your whole account: ticking PSA on a kind of alert covers every domain and every connected PSA, not just one customer.
  • In-app, Email and PSA are separate. You can push an alert to your PSA without emailing it, or the other way around.

Step two: configure the integration's Alerts tab

Open Integrations, click Configure on the PSA integration, and go to the Alerts tab. Turn on the main switch "Open tickets for DMARCER alerts". While this is off, that integration ignores every alert, no matter what is ticked on the Alerts settings page.

  • New-ticket status: the status a freshly opened ticket starts in.
  • Self-heal status: where DMARCER moves the ticket once the problem clears. Leave it blank and tickets will not close on their own, so you will need to close them in the PSA yourself.
  • Default team and Default ticket type: which team the ticket is assigned to and how it is classified, both chosen from your PSA's own lists.
  • Severity to PSA priority: DMARCER raises alerts at three levels of severity (info, warning, critical). Match each one to a priority in your PSA. The ticket opens at that priority, and DMARCER raises it if the severity gets worse. Leave any row set to (PSA default) to let the PSA decide.
  • Subject template: the wording of the ticket subject line. The placeholders {AlertTitle}, {Domain} and {Severity} are filled in for you. Leave it blank for the standard wording, which starts with "DMARCER:" followed by the {AlertTitle} and the {Domain}.

Use the Send Test Ticket button on this tab to check the connection from end to end. It picks the first customer linked on the integration and creates a clearly marked test ticket in exactly the same way a real alert would, using the Alerts settings you last saved. If you have just changed the form, click Save first, and remember to close the test ticket in your PSA afterwards.

How a domain reaches the right PSA customer

Pushing an alert is not enough on its own: DMARCER also has to know where the ticket belongs. A domain will only raise a ticket when it can be matched to a customer in your PSA.

  • The domain must be assigned to a Customer in DMARCER.
  • That customer must be linked to a customer in your PSA. Open the customer's row, click the PSA link icon and link them to the matching PSA customer.
  • For PSAs whose tickets attach to an asset (such as HALO), the domain also needs to be linked to a matching PSA asset. Go to Configure then Assets then Sync now to create that link. For PSAs whose tickets attach to the client only (such as SuperOps), no asset link is needed.

When tickets self-heal, and when they do not

Self-heal only applies to the kinds of alert that DMARCER re-checks against live data on every cycle, so that the problem no longer being there is a genuine "all clear". These include domain expiry, deliverability drops, DMARC reporting going quiet or having no reporting address set, MTA-STS certificate renewal failures and bursts of TLS-RPT failures.

Alerts that are triggered by a one-off event (for example ownership lost, DMARC reporting lost, blacklist listings and SPF change events) do not close on their own. There is no matching "all clear" for these, so their tickets stay open until someone closes them in the PSA. DMARCER will still open and update them, it just will not close them for you.

Common pitfalls

  • No ticket appeared: check that PSA is ticked for that kind of alert on Alerts then Settings, and that the integration's "Open tickets for DMARCER alerts" switch is on.
  • The domain has no Customer assigned, or the customer is not linked to your PSA: without that link there is nowhere to send the ticket.
  • HALO and other asset-based PSAs need the domain to be linked to an asset. If the customer is linked but the domain is not, go to Configure then Assets and run a sync.
  • Self-heal status left blank: tickets will not close on their own. Set a Self-heal status if you would like DMARCER to resolve them.
  • Expecting one-off alerts to close themselves: ownership, blacklist and SPF-change tickets are closed by hand by design.
  • Anything skipped or failed is recorded. If a ticket is not created, look in the audit feed for a "dispatch skipped" or "dispatch failed" entry: it spells out exactly why, and what to fix.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles