DMARC with WebMon

DMARC: the policy that decides what happens to mail claiming to be yours.

DMARC tells receiving servers what to do with messages that fail SPF and DKIM aligned with your domain, and returns reports of who sends in your name. WebMon processes those reports and moves you from p=none to p=reject safely.

Home · Email security · DMARC

In short

What is DMARC?

What it is

DMARC (Domain-based Message Authentication, Reporting and Conformance) is a public standard published as a TXT record at _dmarc.yourdomain. It defines a policy — none, quarantine or reject — and requests reports about mail sent in your domain's name.

How it works

When a server receives a message, it checks that it passes SPF or DKIM and that the From domain aligns with them. On failure it applies your DMARC policy and sends an aggregate report to the rua address you defined.

Who it's for

Any organization with its own domain that sends mail — marketing, transactional or payroll. It is especially critical for banking, healthcare and government, frequent spoofing targets.

What problem it solves

It prevents exact spoofing of your domain: without DMARC at reject, an attacker can send mail that appears to come from you. With the policy enforced, those messages are rejected or quarantined.

Capabilities

From raw report to enforced policy

Readable reportsTurns the DMARC aggregate XML into understandable sending sources.
SPF/DKIM alignmentShows which sources align and which fail authentication.
Path to rejectGuides you from p=none to p=reject without blocking legitimate mail.
Abuse alertsAlerts when an unknown source attempts to send for your domain.

Why it matters

What your domain gains

FAQ

Frequently asked questions

What do p=none, quarantine and reject mean?

They are the three DMARC policies: none only monitors, quarantine sends suspicious mail to spam and reject blocks it outright. The recommendation is to start at none and advance using report data.

Does DMARC protect on its own?

No. DMARC relies on SPF and DKIM: it checks that at least one passes and aligns with the From domain. Without SPF and DKIM correctly configured, DMARC has nothing to evaluate.

Can moving to reject block my legitimate mail?

It can, if there are legitimate sources left unauthenticated. That is why WebMon first identifies and authenticates all your sources in none mode, and only then raises the policy gradually.

How does WebMon help with DMARC?

WebMon receives and processes your aggregate reports, translates the XML into clear sources, detects abuse and guides you to p=reject, backed by the SGS 24/7 SOC in Costa Rica.

Know who sends in your name.

Diagnose your domain with WebMon and see your DMARC record status today.

Diagnose your domain with WebMon