DMARC Monitoring

DMARC Monitoring That Makes p=reject Safe.

Collects DMARC aggregate reports, parses raw XML source-by-source, and tracks SPF and DKIM alignment for every service sending as your domain.

Book a DMARC walkthrough

Book 30 minutes and we will read your current reports with you, free, no pitch.

Trusted by 500,000+ leading GTM teams

Three steps

Stop reading gzipped XML. Start reading a verdict.

No agent to install and no mail server changes beyond one DNS record you already control. Point rua= at Verifox and the reports start arriving.

001INPUT

Point your rua= tag at Verifox

Publish a DMARC record with our rua= address, or keep your own and forward a copy. No agent to install and no mail server changes beyond the one DNS record you already control.

002ENGINE

We parse every report

Daily RUA reports from Gmail, Yahoo, and every other receiver are unzipped, parsed, and resolved into named services, with SPF and DKIM alignment tracked per source.

003VERDICT

We tell you when to move

The dashboard names every unaligned sender so you can fix it during p=none, then flags the moment your alignment rate is stable enough to move to p=quarantine, then p=reject.

The honest answer

What a DMARC monitor does

Providers already send you a daily accounting of your own mail. A monitor makes it readable.

Every major mailbox provider that receives your email sends a daily accounting of it back to you. These DMARC aggregate reports (RUA reports) are gzipped XML files delivered to whatever address sits in the rua= tag of your DMARC record. Inside each one: every IP that sent mail claiming to be your domain, how many messages it sent, and whether each batch passed SPF and DKIM alignment. The data is gold and the format is hostile. A domain of modest size collects dozens of these files a day, and nobody reads raw XML at that rate. A DMARC monitor receives the reports for you, parses them, resolves IPs into named services, and turns a week of attachments into one table: who sends as you, how much, and what passes.

What the reports show

What does a DMARC report actually tell you?

Providers send you a daily accounting of your own mail in gzipped XML. Parsed, it answers four questions you cannot answer any other way.

Sources

Who is sending as you

Every RUA report is collected, unzipped, parsed, and merged into one source-by-source view with IPs resolved to named services. Almost every company finds senders it forgot — the billing system, the recruiting tool, an agency still running campaigns.

Verifox clay fox presenting a clay ledger board with named sender tags beside a pile of parsed clay report files.
Alignment

Passing is not the same as aligned

This is the part that trips everyone. A message can pass SPF outright and still fail DMARC, because the domain that passed is not the domain in the From line. We chart per-source SPF and DKIM alignment, which is the number enforcement actually depends on.

Verifox clay fox holding two clay envelopes side by side, one with matching green domain tags and one with mismatched tags.
Policy

When it is safe to tighten

The engine reads your live alignment data and tells you whether to hold at p=none, step to quarantine, or commit to reject. Each move is gated on what your own mail is doing, not on a calendar or a vendor’s preferred timeline.

Verifox clay fox beside a three-step clay staircase rising from grey to amber to green, with a green flag at the top.
Threats

A spoofer or just a forward

Forwarded mail breaks SPF but keeps its DKIM signature; a spoofer fails both. We separate the two patterns, so mailing lists and auto-forwards never scare you out of enforcement and a real impersonation attempt raises an alert the day it appears.

Verifox clay fox holding a green clay shield between a masked clay impostor envelope and a harmless forwarded one.
One record, every report

Everything the monitor parses

Publishing a DMARC record is the easy half. Reading the reports it generates is the half that gets you safely to enforcement.

DMARC engine
5

weeks to full
enforcement

Every report is parsed as it arrives, so a broken sender surfaces the same week.

Every sender, named

Who sends as you, and which of them fails alignment.

Feb 2024 enforcement

When Google and Yahoo started requiring this of bulk senders.

p=reject, safely

The only policy that stops spoofing, reached without breakage.

1 domain free

Monitored free, no card, so you can start reading reports today.

Credits never expire

1,000 free on signup. 2,500 with a work email. Pay as you go after.

Start free

Reports are never shared

Parsed in your account only. SOC 2 · GDPR · CCPA.

Pricing

Pay once, or not at all

Most tools reset your balance every month. Verifox sells credits that sit in your account until you spend them.

FreeProve it on your own list before you spend anything.$0

forever

1,000credits on signup

No card required

2,500 with a work email

Free includes

  • All 9 checks included
  • Full API and bulk CSV
  • Catch-all confidence scoring
  • No card required
Most popular
Credit packsBuy once, spend whenever. Slide to price your list.$59

one time

10,000credits

$0.0059 eachSAVE 34%

Everything in Free, plus

  • Credits never expire
  • Verify or find from one pool
  • Up to 79% off at volume
  • No contract, no minimum
Verifox ONECredits land monthly and stack on your balance.$79

per month

15,000credits a month

$0.0053 each

Unused credits roll over

Everything in packs, plus

  • Unused credits roll over
  • Our lowest per-email rate
  • 50 requests per second API
  • Cancel anytime

One credit verifies one address; a find costs 10. All prices in USD, checkout via Stripe.

What teams are saying

Built for the teams that ship outbound

Growth leads, marketers, and engineers running real campaigns on real lists, with a verified email on every byline.

Thomas George, GTM Lead at Stripe

90% lower bill, 0.4% bounces

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.
Thomas G.GTM Lead, Stripe
Brittany King, GTM Lead at HubSpot

Catch-all finally has a verdict

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.
Brittany K.GTM Lead, HubSpot
Dale Micallef, GTM Lead at Slack

Reputation rebuilt in 6 weeks

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.
Dale M.GTM Lead, Slack
Erica Kovalkoski, GTM Lead at Discord

0.7% bounce on 50k

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.
Erica K.GTM Lead, Discord
Greg Lindsay, GTM Lead at OpenAI

MCP in 10 minutes

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.
Greg L.GTM Lead, OpenAI
Rini Vasana, Product Manager at Vercel

10k/min held under 400ms

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.
Rini V.Product Manager, Vercel
Jonathan Aharon, GTM Lead at MongoDB

Hygiene that doesn't break pipeline

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.
Jonathan A.GTM Lead, MongoDB
Emma Fox, GTM Lead at Linear

Bulk that actually ships

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.
Emma F.GTM Lead, Linear
David Hare, GTM Lead at Snowflake

Scores you can act on

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.
David H.GTM Lead, Snowflake
Trust & compliance

Enterprise-grade security and scale

Every layer of the stack carries a third-party attestation, so you can ship into regulated industries without rebuilding your compliance posture.

  • Claymation Japanese hanko seal in jade-green clay with a twisted shimenawa rope rim, the words SOC 2 TYPE II embossed in cream clay on its face.

    SOC 2 Type II

    Independently audited to the SOC 2 Type II standard.

  • Claymation Japanese hanko seal in cobalt-blue clay with a twisted shimenawa rope rim, the word GDPR embossed in cream clay on its face.

    GDPR

    Built for the EU with full GDPR data-subject rights.

  • Claymation Japanese hanko seal in rose-pink clay with a twisted shimenawa rope rim, the word CCPA embossed in cream clay on its face.

    CCPA

    California opt-out, do-not-sell, plus DSAR handling.

  • Claymation Japanese hanko seal in terracotta clay with a twisted shimenawa rope rim, the text ISO 27001 embossed in cream clay on its face.

    ISO 27001

    Information security held to the ISO 27001 standard.

  • Claymation Japanese hanko seal in lilac-purple clay with a twisted shimenawa rope rim, the text ISO 42001 embossed in cream clay on its face.

    ISO 42001

    AI governance aligned to the new ISO 42001 standard.

Free field manual

The Dead List

An investigation into the money leaking out of your list - and the nine checks that decide whether your email is read, or never arrives at all.

The Dead List field manual, held up by the Verifox fox
Get the free manual

57 pages, free PDF, no signup

Common questions

DMARC reports, decoded

What teams ask between publishing p=none and daring to type p=reject: report formats, alignment mechanics, and subdomain traps.

What is a DMARC aggregate (RUA) report?

A DMARC aggregate report is a daily XML file that mailbox providers like Gmail and Yahoo send to the rua= address published in your DMARC record. It lists every IP that sent mail claiming your domain, the message counts, and the SPF and DKIM alignment result for each batch. Verifox receives these reports, parses the XML, and resolves the IPs into named services, so you read a dashboard instead of gzipped attachments.

What is the difference between RUA and RUF reports?

RUA reports are aggregate: daily per-source counts of messages with pass and fail totals, no message content. RUF reports are forensic: redacted copies of individual failing messages. In practice RUA carries nearly all the value, because most large providers, Gmail included, decline to send RUF for privacy reasons. Verifox accepts both, but every policy recommendation we make is built from your aggregate data, which arrives reliably from every major receiver.

How long should I stay at p=none before tightening my policy?

Two weeks is the practical minimum; domains with many sending services need longer. p=none blocks nothing, and its whole job is to collect aggregate reports until every legitimate source is identified and aligned. Move when your alignment rate is stable and high, not on a calendar date; the monitor flags the moment that holds. Start with a free DMARC, DKIM, and SPF check to see which policy your domain publishes today.

Will p=reject block my newsletters or CRM emails?

Not if they are aligned first. Tools like Mailchimp, HubSpot, and SendGrid send from their own servers, so out of the box they fail SPF alignment. Each one offers the fix: a custom return path for SPF and a DKIM key that signs with your domain. The monitor lists exactly which of your senders would fail under p=reject, so you repair them during the p=none phase while nothing is being blocked.

What do the Google and Yahoo bulk-sender rules require?

Since February 2024, anyone sending 5,000 or more daily messages to Gmail or Yahoo must publish a DMARC policy of at least p=none, authenticate with both SPF and DKIM, align the visible From domain, offer one-click unsubscribe, and keep spam complaints under 0.3%. Smaller senders still need SPF or DKIM. Mail that misses the bar gets throttled or rejected, which is why DMARC monitoring stopped being optional for bulk senders.

How does the sp= subdomain policy tag work?

The sp= tag sets a separate DMARC policy for subdomains; without it, subdomains inherit your p= value. It matters because attackers deliberately spoof forgotten subdomains like mail.yourdomain.com or billing.yourdomain.com, where nobody is watching. Verifox tracks every subdomain that appears in your aggregate reports and warns you when sp=, or a missing record on a delegated subdomain, leaves one of them weaker than your organizational policy.

How is SPF alignment different from DKIM alignment?

SPF alignment compares the Return-Path domain with your visible From domain; DKIM alignment compares the d= domain in the signature. A message passes DMARC when either one passes and aligns. The practical difference is forwarding: it rewrites the Return-Path and breaks SPF, while a DKIM signature survives intact. That makes aligned DKIM the backbone of a safe p=reject. If one source keeps failing, the free DKIM tester shows whether its signature validates at all.

What does the pct= tag do in a DMARC record?

pct= applies your policy to only a percentage of failing mail. At p=quarantine with pct=25, a quarter of failing messages go to spam and the rest are treated as p=none. It is a throttle for nervous rollouts. Treat it as a short ramp, not a destination: a long-lived pct below 100 leaves a permanent gap spoofed mail can ride through, and some receivers do not honor the tag at all.

Is the Verifox DMARC monitor free?

Yes. Monitoring is free for one domain, with unlimited aggregate reports and no card required. Signing up also grants 1,000 free credits, or 2,500 with a work email, usable across the whole platform. Additional domains run on the same pay-as-you-go credits, which never expire, and the pricing page shows rates localized for your region.

Can I pull DMARC data through the API?

Yes. Per-source alignment rates, parsed report history, policy state, and spoofing alerts are all exposed over REST and documented in the API reference. Webhooks push new-source and failure-spike events into Slack or your own tooling, and AI agents can read the same data through the native MCP server. Most teams wire it next to email verification so hygiene and authentication share one pipeline.