Welcome to DMARCER and how it works

A friendly starting guide to DMARCER: what it does to protect your domain's email, and the first things to set up, from adding a domain to working safely towards full DMARC enforcement.

Published 3 Jul 2026 36

DMARCER helps you find and fix the weaknesses that let attackers send email as your domain, and shows your progress over time. It looks after SPF, DKIM, DMARC, DNSSEC and MTA-STS for you, gathers the DMARC and TLS reports that mailbox providers send back, turns all of that into a clear security score, and guides you safely towards full enforcement. This article is your starting point: it explains what the product does and walks you through the first things to set up.

What DMARCER does

At its heart, DMARCER keeps an eye on the email security of each domain you add and gives you one place to act on it. The main things it does are:

  • Scores each domain across SPF, DKIM, DMARC, MTA-STS, TLS-RPT, DNSSEC and your MX (mail) record, and tracks deliverability using your real report data.
  • Collects DMARC aggregate reports (shown under Delivery Reports) so you can see exactly who is sending email as you, and which sources pass or fail.
  • Collects forensic (failure) reports under Forensic Reports, so you can look more closely at individual failures.
  • Helps you fix issues, including hosted records and, where a DNS provider is connected, publishing records for you.
  • Guides you step by step towards DMARC enforcement (a policy of quarantine, then reject), without breaking your legitimate mail.
  • Adds Blacklist Monitoring and Brand Watch, so you are warned about reputation problems and look-alike domains too.

Signing in and the Overview dashboard

If you signed up yourself, you chose Business or MSP on the sign-up page, verified your email, and your account was created. New accounts have multi-factor authentication (MFA) switched on, so the first time you sign in you will be asked to set up an authenticator app. Do keep this safe: it protects every domain you manage.

After signing in you land on Overview, your dashboard. It sums up the health of all your domains and suggests your next actions, so it is the best place to start each visit. The menu on the left takes you to the rest of the product: Domain Management, Delivery Reports, Forensic Reports, Enforcement, Blacklist Monitoring and Brand Watch. If you are an MSP you will also see Customers, where domains are grouped by the client they belong to.

Adding your domains

Nothing is monitored until you add a domain. Open Domain Management and click Add Domains. The dialog asks for a few things:

  • Monitoring Region: where reporting and monitoring for this domain are handled. A sensible choice is already picked for you based on your account country, so in most cases you can leave it as it is.
  • Domain Type: choose Standard for domains you send mail from (full monitoring), or Parked for domains you own but never send from. A Parked domain is watched as a protective placeholder, and tells you straight away if any sending activity appears. If a mail (MX) record or a sending SPF record later shows up, DMARCER moves it to Standard for you automatically.
  • Domains (one per line): paste one domain per line, for example example.com. You can add several at once.

Click Add Domains to save. If you previously removed a domain and add it again, DMARCER brings the existing record back rather than creating a duplicate. MSP accounts can also assign each domain to a customer, so reporting and the client portal stay neatly grouped.

Verifying ownership

Before DMARCER will manage hosted records or let you act on a domain, it checks that you control the DNS. Open the domain and choose Verify Domain Ownership. You will be shown a DNS TXT record to add at the root of the domain, with a Name and a Value you can copy. Add that record at your DNS host.

Checking happens automatically, and you can press Recheck Now once the record is published. DMARCER looks the record up directly, so there is no waiting around for old DNS information to expire. If your DNS provider is connected to DMARCER, you may instead see a Publish now option that adds the verification record for you. This does not affect your mail in any way.

Understanding your Domain Security Score

Each domain you add gets a Domain Security Score out of 100, with a letter grade from A down to F. The score reflects how complete and how strong your email security setup is, and it updates as your records and report data change. Open the why-this-score view on a domain to see a breakdown of the points you have earned against the points available.

There are two ways of scoring, and the right one is chosen for you based on the Domain Type:

  • Standard (mail-sending) domains earn points for a valid SPF record set to reject anything not on the list, DKIM, a DMARC record with reporting turned on and a strong policy, MTA-STS in enforce mode, DNSSEC, a present mail (MX) record, TLS-RPT reports flowing, and real-world deliverability from your DMARC pass rate.
  • Parked domains are scored as a safe-by-design placeholder: they are rewarded for an SPF record set to reject, a DMARC reject policy, DNSSEC and reporting, and are not marked down for missing DKIM or MTA-STS they do not need.

If there is something we do not have data for yet (for example deliverability on a brand-new domain before any reports arrive), it is simply left out of the calculation rather than scored zero, so you are never unfairly marked down for being early in the process.

From monitoring to enforcement

The goal is to reach a DMARC policy of reject, where mail that pretends to be your domain and fails the checks is turned away by receivers. Getting there safely means first seeing who sends as you, then sorting out your genuine senders, then tightening the policy in stages.

  • Use Delivery Reports to read your DMARC aggregate data: which sending sources exist and whether they pass the SPF and DKIM checks.
  • Use Forensic Reports to look into individual failures in more detail.
  • Use Enforcement to follow the guided journey from a monitoring policy (none) through quarantine to reject, only moving on once your genuine senders are passing.

DMARC reports are not instant: after a record goes live it usually takes 24 to 72 hours for the first reports to start arriving once receivers notice it, so give each step a little time before judging it.

Common pitfalls

  • Expecting data straight away. A newly added domain shows little until reports come in, so allow up to 24 to 72 hours after publishing your records.
  • Forgetting to verify ownership. Until the TXT record is in place and rechecked, hosted-record actions stay locked.
  • Choosing the wrong Domain Type. Marking a sending domain as Parked, or the other way round, applies the wrong scoring and the wrong alerts. DMARCER moves a Parked domain to Standard for you only when it spots a mail (MX) record or a sending SPF record.
  • Jumping straight to reject. Work through the Enforcement stages in order so you do not block legitimate mail before its sources are passing.
  • Losing your MFA device. Because MFA is required, keep a backup so you do not lock yourself out of every domain at once.

Was this article useful?

Be the first to vote.
Got feedback for our team? Send us a comment

Related articles