Every domain you add to DMARCER gets a security score out of 100, so you can see at a glance how well it is protected. We update it for you automatically, and it comes with a letter grade so you can spot weaker domains without having to read through all the underlying records. This score is based on the live signals we monitor for your domains, and it is separate from our public Domain Security Benchmark, which uses simpler checks for any domain on the internet.
Where you see the score
On the Domains page you will find a Score column. Each domain shows a coloured badge in the form "score (grade)", for example "82 (A)". The colour matches the grade, so a green A or a red E or F stands out straight away. A dash means the domain has not been scored yet, because its first scoring run has not happened.
Click any score badge to open the Security Score breakdown. The window lists every part of the score, how many points it earned out of the points available, a short explanation, and a progress bar. At the top you will see the total points that apply and whether the domain was scored as a Standard or Parked domain, and at the bottom you will see when it was last scored.
The same score also rolls up onto the Customers grid (one score per customer) and the company view, so you can compare customers and companies at a glance.
How the score is calculated
We add up the points a domain has earned, divide by the points that actually apply to it, and turn that into a score out of 100. The important idea is that anything we do not have data for yet (for example a brand new domain with no delivery history) is simply left out of the sum rather than scored as zero, so a young domain is not punished for things it has not yet had the chance to show. The score rewards records that are genuinely doing their job, not just being present.
What each component is worth (standard, mail-sending domains)
For a normal mail-sending domain, the points are split across these areas:
- SPF: points for having exactly one valid SPF record that does not contain an error serious enough to make receivers treat SPF as broken, plus more points for how strictly it is set. A hard fail (-all) earns the full amount, a soft fail (~all) earns part of it, and a neutral or pass-all (?all or +all) earns only the points for having the record.
- DMARC: points for a valid record, for having reporting switched on (a rua= address that receives the aggregate reports), and for the policy itself. A reject policy earns the most, quarantine less, and none only a little. A pct= setting below 100 means the policy is only partly enforced, so the policy points are reduced to match.
- DKIM: awarded when we have actually seen a working DKIM key in use for the domain (from your report data), rather than just assuming it is there.
- MTA-STS: points for a valid policy, with enforce mode earning more than testing mode.
- DNSSEC: awarded when DNSSEC is enabled for the domain.
- MX records: awarded when we can find an MX record for the domain. A mail-sending domain with no MX record cannot handle mail properly, so a missing one costs points.
- TLS-RPT: awarded once we have received at least one TLS report, which tells us your TLS-RPT policy is working. For roughly the first 24 hours after you publish it, no report will have arrived yet, and that is perfectly normal.
- Deliverability (90-day): your DMARC pass rate over the last 90 days. This is the one signal that only DMARCER can give you, because it comes from monitoring your domain over time. It only counts once we have report data for the domain; until then it is left out of the calculation rather than scored as zero.
Parked domains are scored differently
A domain marked as parked is scored against a different set of checks that suit a domain not used for email. A correctly parked domain (no mail, SPF -all, DMARC reject, DNSSEC enabled, and reporting set up) scores highly because it is secure by design. It is not marked down for missing DKIM, MTA-STS or delivery history, because a parked domain does not need them. If a domain is genuinely sending mail, make sure it is not marked as parked, otherwise it will be scored the wrong way.
RFC compliance findings reduce the score
Once the points are worked out, we subtract a small penalty for any open RFC compliance findings on the domain (the final score always stays between 0 and 100). This is why a domain whose six headline checks look healthy can still score lower than you might expect. In the breakdown window, an "RFC compliance findings" line shows the total amount deducted; open the Findings tab for the domain to see and resolve each issue. Any change to how findings are weighted affects future scores, not the score already saved from the last run.
Grades and roll-ups
The number turns into a letter grade: A for 80 and above, B for 65 to 79, C for 50 to 64, D for 35 to 49, E for 20 to 34, and F below 20. A customer's score is simply the average of their domains' scores, and a company's score is the average across all of that company's domains. Parked domains are included in these averages, scored against the parked checks.
When it updates, and common things to watch for
The score is recalculated regularly (every hour by default), and also whenever our monitoring spots a change to one of the signals. If you run a manual recheck on a domain, the score updates straight away from the freshly checked results, so you do not have to wait for the next update to see the effect of a change.
- A new domain shows a dash until its first scoring run has happened. This is normal.
- Deliverability is left out (not counted as zero) until report data arrives, so a young domain is not dragged down by it.
- DKIM only counts once we have actually seen a working DKIM key in your reports. If you have published DKIM but no mail has been sent yet, it may not show as earned.
- TLS-RPT relies on a report having arrived, so please allow up to about a day after publishing before it counts.
- A DMARC pct= below 100, or a policy of quarantine or none, only enforces in part, so the policy points are reduced. Move to p=reject with pct=100 for the full amount.
- Open RFC findings can hold a score down even when SPF, DKIM, DMARC, MTA-STS, DNSSEC and MX all look fine. Check the Findings tab.
- If a sending domain scores oddly high or low, check it has not been set to parked by mistake (or the other way round), since that changes the whole way it is scored.