Cybersecurity › Email Security › DMARC Monitoring

Managed DMARC monitoring.
From reports to a p=reject policy.

Google, Microsoft, Yahoo and other receivers tell you every day who is sending mail on behalf of your domain. They do it with XML reports nobody reads. We read them every hour, turn them into concrete actions and walk the domain to p=reject one step at a time. You receive sheets and summaries: no tool to learn.


The DMARC record is there. The monitoring is not.

Many business domains published a DMARC record to satisfy the requirements of the large receivers and stopped at p=none: reports land in a mailbox nobody opens and the policy blocks nothing. Monitoring is the work that turns that record into protection: understanding who sends, authorising the legitimate senders, tightening the policy when the numbers allow it.

p=none

Observe only. Messages that fail authentication are still delivered: the domain remains usable for phishing and spoofing in your name, even with the record published.

XML

The format of aggregate reports: one file per receiver per day, with IP addresses, volumes and outcomes. Useful only if someone reads it, matches it against the systems that really send and acts.

10 lookups

The DNS lookup limit beyond which an SPF record fails silently. Every service added with an include consumes some. Counting and reducing them is part of the monitoring.

What the service does

Six activities, every hour, on every domain.

Not a dashboard to check: an operating cycle that runs on its own and calls an operator when a decision is needed.

Reading the aggregate reports

We receive the DMARC reports that Google, Microsoft, Yahoo and other receivers send for your domains and read them every hour. Every IP address that sent in your name is traced back to a recognisable source.

Plain-language diagnosis, with the action

Every source gets a diagnosis with the same labels the client finds on the sheet: your server to fix, third-party service to authorise, forwarding, blocked abuse. Next to it, the action to take. No XML, no tables of IP addresses to interpret.

DNS checks from the authoritative name servers

We check SPF, DKIM and DMARC every hour by reading DNS at the source, not from caches. We count SPF lookups, propose how to get back under the limit of ten and generate the records ready to publish.

Guided path to p=reject

A readiness score shows how far enforcement is and what the next step is. The domain moves from none to quarantine to reject only when legitimate sources authenticate, and forwarders are recognised before the policy is tightened.

Alerts within an hour of the report, summary on Monday

Within an hour of a report arriving or a DNS change, operators receive an email alert if an unknown sender appears, a DKIM signature stops passing, SPF exceeds its limits, a DMARC or SPF record changes or disappears, or reports stop arriving. Receivers send reports once a day. Every Monday, a weekly summary.

Domain sheet as PDF

For every domain we produce a printable sheet: figures for the last thirty days, DNS configuration, stage of the path, what has been done and who sends mail in your name. It is the document we hand to the client and that holds up in an audit.

How it works

From the XML report to the policy that protects.

The cycle starts at the receiving servers and ends in your domain’s DNS. In between is the work nobody usually does: read, understand, authorise, tighten.

Source

Aggregate reports

Google, Microsoft, Yahoo and other receivers send a daily report for every DMARC-enabled domain. We receive them in a dedicated mailbox and read them every hour.

Analysis

Diagnosis

Every source gets a plain-language diagnosis: your server to fix, third-party service to authorise, forwarding, blocked abuse. Next to it, the action to take.

AtWorkStudio

Intervention

We authorise senders in SPF, enable DKIM where it is missing, reduce lookups and publish the records generated by the platform.

Outcome

Enforcement

The domain moves to p=quarantine and then to p=reject when the readiness score allows it. Monitoring continues and alerts stay active.

Managed service

You receive the sheet.
We do the work.

We do not sell a dashboard. AtWorkStudio configures the records, authorises the senders, brings the domain to enforcement and keeps monitoring it. The client receives sheets and summaries and does not have to learn a tool.

The operating platform, DMARC Reaper, is reserved for AtWorkStudio operators. For organisations on Microsoft 365 the service sits alongside Defender for Office 365 and our ACN-qualified Email Security Gateway: authentication protects the domain, the gateway protects the mailboxes.

Azure Italy North

Reports, history and sheets reside in the Azure Italy North region. No third-party resources in the platform’s pages.

13 months

Retention of reports and history: enough to compare a full year and document when a source appeared or was authorised.

Every Monday

A weekly summary: what changed, which sources appeared, where the path stands. The PDF sheet is generated when needed, for an audit or a meeting.

ISO 27001 · 27017 · 27018 · 9001

A service delivered by a company certified for information security, cloud security, personal data protection and quality. Members of Clusit.

Frequently asked questions about DMARC monitoring

The questions we hear before activating the service.

Want to know who is sending mail on behalf of your domain?

Tell us how many domains you have and which systems send email. We tell you where you stand and what it takes to reach p=reject. DMARC monitoring completes email security and integrates with DNS management for your business domain.