Talk to the founders

Monitor a sending domain

We'll watch this domain's deliverability posture and email you only when something changes — DMARC downgraded or removed, SPF broken or near the lookup limit, a new blocklist listing — plus DKIM key changes at any selector your DMARC reports show you signing with. Read-only; we never change anything.

Every alert says what the change does to mail you send and the one thing to do about it — see what these alerts mean.

Sample — what your dashboard shows
Senders in your DMARC reports
Every source sending as you — who it is, how much, and which mechanism actually authenticated.
Last 7 days · 1,121 messages · reports from Google and Yahoo · 192.0.2.x addresses below are documentation examples
SenderVolumeSPFDKIMDMARC
192.0.2.11
Google Workspace
942passpass100%
198.51.100.7
an ESP you use
120passfail75%
203.0.113.44
Not yet identified
59failnone0%
What this actually tells you: the ESP's SPF passes but its DKIM signature does not, so 25% of its mail has nothing left to align on — that points at DKIM setup, and the report names the selector to check. The unidentified source signs nothing and passes nothing: it is either a service nobody set up or someone spoofing you, and the reports alone can't tell those apart — the volume and the sending pattern will.

We email a confirmation link first (double opt-in). Your domain and alert address are kept while monitoring is active — unsubscribe and they go. Posture history and DMARC report data roll off after 29 days on the free tier. See Privacy.

Deliverability monitoring FAQ

What does monitoring watch?

Three separate things, and they're worth keeping apart. (1) Your SENDING authentication in DNS — SPF and DMARC — checked once a day. (2) Your SENDING REPUTATION, by checking the IPs we can find for you and your domain against the major blocklists (Spamhaus, Barracuda, SpamCop). (3) Your INBOUND transport security — whether you advertise MTA-STS — reported for completeness but kept out of your sending score, because it protects mail coming to you, not mail you send. DKIM sits slightly apart: DNS gives no way to list your selectors, so we can only watch keys at selectors we've actually seen in your DMARC reports. We email you only when something changes, and it's strictly read-only.

What happens after I sign up?

We email a confirmation link — click it and monitoring starts; your first scan runs within 24 hours. If you also turned on DMARC report reading, there's one quick extra step: add the short verification TXT record we show you (proving you own the domain), then point your domain's DMARC 'rua' tag at the reporting address we give you. After that, reports start flowing into your dashboard automatically.

What will I actually see?

A dashboard for each domain. Up top, a posture summary with a gap score and a plain-English list of any changes — or 'no changes detected yet,' which is the good outcome. Below it, a blocklist card showing your sending IPs' current reputation across the lists we check. If DMARC reports are on, you also get a Senders table: every IP sending as you, who it is (Google Workspace, your ESP, or an unknown/likely-spoofing source), how many messages receivers saw, and what share passed DMARC — plus a recommended action for anything that isn't aligned.

When will I actually hear from you?

Only when something changes. There's no daily digest and no noise — a quiet inbox means your posture is holding. After the first scan we email you after the next daily check that spots the change — so usually within 24 hours of it happening, not instantly. DNS caching can add a little more.

What's the difference from a one-time audit?

A one-time check tells you your posture right now. Monitoring watches it continuously and catches the silent break weeks later — the DMARC record someone loosened, the blocklist listing that appeared overnight, the DKIM key rotated at a selector we've seen you use — on the next daily check, not the next time you remember to look.

Does it tell me if I get blocklisted?

Yes, with one honest limit on coverage. We check daily against Spamhaus, Barracuda and SpamCop and email you when a NEW listing appears, deduplicated so one listing means one alert rather than a daily reminder. The limit is which IPs we can see: we derive them from your SPF record and your MX hosts, and — if you enable DMARC report reading — from the sending IPs your reports actually show. If you send through a shared provider whose SPF is a broad include, there may be no specific IP for us to check, so treat a clean result as 'nothing listed among the addresses we could identify', not 'nothing listed anywhere'. A listing is still one of the most common silent causes of a deliverability drop, because the rejection happens at the receiving server and you usually get no bounce naming the list.

What are DMARC reports, and why enable that option?

DMARC aggregate (RUA) reports are the feedback mailbox providers send about your domain. Turn the option on and we ingest them so you can see who is sending as you — legitimate services and spoofers alike — and whether they pass authentication. That's what powers the Senders table above; it needs the quick ownership + 'rua' setup described earlier.

Do you change anything on my domain?

No. Monitoring is strictly read-only — we never touch your DNS or your mail flow. We tell you what changed and what it means; you decide what to do about it.

What do you store, and for how long?

Different things have different clocks, and it's worth being precise. Your ENROLLMENT — the domain and the alert email address — is kept for as long as monitoring is active, because that IS the monitoring; unsubscribe and it goes. Raw DMARC report attachments are held only long enough to parse and replay if a parse fails, then dropped. The derived data — posture history and DMARC report rollups — rolls off after ${RETENTION(env)} days on the free tier; longer history is a paid feature. See our Privacy page for details.