Monitor a sending domain
We'll watch this domain's deliverability posture and email you only when something changes — DMARC downgraded or removed, SPF broken or near the lookup limit, a new blocklist listing — plus DKIM key changes at any selector your DMARC reports show you signing with. Read-only; we never change anything.
Every alert says what the change does to mail you send and the one thing to do about it — see what these alerts mean.
| Sender | Volume | SPF | DKIM | DMARC |
|---|---|---|---|---|
| 192.0.2.11 Google Workspace | 942 | pass | pass | 100% |
| 198.51.100.7 an ESP you use | 120 | pass | fail | 75% |
| 203.0.113.44 Not yet identified | 59 | fail | none | 0% |
We email a confirmation link first (double opt-in). Your domain and alert address are kept while monitoring is active — unsubscribe and they go. Posture history and DMARC report data roll off after 29 days on the free tier. See Privacy.
Deliverability monitoring FAQ
What does monitoring watch?
Three separate things, and they're worth keeping apart. (1) Your SENDING authentication in DNS — SPF and DMARC — checked once a day. (2) Your SENDING REPUTATION, by checking the IPs we can find for you and your domain against the major blocklists (Spamhaus, Barracuda, SpamCop). (3) Your INBOUND transport security — whether you advertise MTA-STS — reported for completeness but kept out of your sending score, because it protects mail coming to you, not mail you send. DKIM sits slightly apart: DNS gives no way to list your selectors, so we can only watch keys at selectors we've actually seen in your DMARC reports. We email you only when something changes, and it's strictly read-only.
What happens after I sign up?
We email a confirmation link — click it and monitoring starts; your first scan runs within 24 hours. If you also turned on DMARC report reading, there's one quick extra step: add the short verification TXT record we show you (proving you own the domain), then point your domain's DMARC 'rua' tag at the reporting address we give you. After that, reports start flowing into your dashboard automatically.
What will I actually see?
A dashboard for each domain. Up top, a posture summary with a gap score and a plain-English list of any changes — or 'no changes detected yet,' which is the good outcome. Below it, a blocklist card showing your sending IPs' current reputation across the lists we check. If DMARC reports are on, you also get a Senders table: every IP sending as you, who it is (Google Workspace, your ESP, or an unknown/likely-spoofing source), how many messages receivers saw, and what share passed DMARC — plus a recommended action for anything that isn't aligned.
When will I actually hear from you?
Only when something changes. There's no daily digest and no noise — a quiet inbox means your posture is holding. After the first scan we email you after the next daily check that spots the change — so usually within 24 hours of it happening, not instantly. DNS caching can add a little more.
What's the difference from a one-time audit?
A one-time check tells you your posture right now. Monitoring watches it continuously and catches the silent break weeks later — the DMARC record someone loosened, the blocklist listing that appeared overnight, the DKIM key rotated at a selector we've seen you use — on the next daily check, not the next time you remember to look.
Does it tell me if I get blocklisted?
Yes, with one honest limit on coverage. We check daily against Spamhaus, Barracuda and SpamCop and email you when a NEW listing appears, deduplicated so one listing means one alert rather than a daily reminder. The limit is which IPs we can see: we derive them from your SPF record and your MX hosts, and — if you enable DMARC report reading — from the sending IPs your reports actually show. If you send through a shared provider whose SPF is a broad include, there may be no specific IP for us to check, so treat a clean result as 'nothing listed among the addresses we could identify', not 'nothing listed anywhere'. A listing is still one of the most common silent causes of a deliverability drop, because the rejection happens at the receiving server and you usually get no bounce naming the list.
What are DMARC reports, and why enable that option?
DMARC aggregate (RUA) reports are the feedback mailbox providers send about your domain. Turn the option on and we ingest them so you can see who is sending as you — legitimate services and spoofers alike — and whether they pass authentication. That's what powers the Senders table above; it needs the quick ownership + 'rua' setup described earlier.
Do you change anything on my domain?
No. Monitoring is strictly read-only — we never touch your DNS or your mail flow. We tell you what changed and what it means; you decide what to do about it.
What do you store, and for how long?
Different things have different clocks, and it's worth being precise. Your ENROLLMENT — the domain and the alert email address — is kept for as long as monitoring is active, because that IS the monitoring; unsubscribe and it goes. Raw DMARC report attachments are held only long enough to parse and replay if a parse fails, then dropped. The derived data — posture history and DMARC report rollups — rolls off after ${RETENTION(env)} days on the free tier; longer history is a paid feature. See our Privacy page for details.