Point your rua= tag at Verifox
Publish a DMARC record with our rua= address, or keep your own and forward a copy. No agent to install and no mail server changes beyond the one DNS record you already control.
DMARC Monitoring
Collects DMARC aggregate reports, parses raw XML source-by-source, and tracks SPF and DKIM alignment for every service sending as your domain.
Book 30 minutes and we will read your current reports with you, free, no pitch.
Trusted by 500,000+ leading GTM teams
No agent to install and no mail server changes beyond one DNS record you already control. Point rua= at Verifox and the reports start arriving.
Publish a DMARC record with our rua= address, or keep your own and forward a copy. No agent to install and no mail server changes beyond the one DNS record you already control.
Daily RUA reports from Gmail, Yahoo, and every other receiver are unzipped, parsed, and resolved into named services, with SPF and DKIM alignment tracked per source.
The dashboard names every unaligned sender so you can fix it during p=none, then flags the moment your alignment rate is stable enough to move to p=quarantine, then p=reject.
Providers already send you a daily accounting of your own mail. A monitor makes it readable.
Every major mailbox provider that receives your email sends a daily accounting of it back to you. These DMARC aggregate reports (RUA reports) are gzipped XML files delivered to whatever address sits in the rua= tag of your DMARC record. Inside each one: every IP that sent mail claiming to be your domain, how many messages it sent, and whether each batch passed SPF and DKIM alignment. The data is gold and the format is hostile. A domain of modest size collects dozens of these files a day, and nobody reads raw XML at that rate. A DMARC monitor receives the reports for you, parses them, resolves IPs into named services, and turns a week of attachments into one table: who sends as you, how much, and what passes.
Providers send you a daily accounting of your own mail in gzipped XML. Parsed, it answers four questions you cannot answer any other way.
Every RUA report is collected, unzipped, parsed, and merged into one source-by-source view with IPs resolved to named services. Almost every company finds senders it forgot — the billing system, the recruiting tool, an agency still running campaigns.

This is the part that trips everyone. A message can pass SPF outright and still fail DMARC, because the domain that passed is not the domain in the From line. We chart per-source SPF and DKIM alignment, which is the number enforcement actually depends on.

The engine reads your live alignment data and tells you whether to hold at p=none, step to quarantine, or commit to reject. Each move is gated on what your own mail is doing, not on a calendar or a vendor’s preferred timeline.

Forwarded mail breaks SPF but keeps its DKIM signature; a spoofer fails both. We separate the two patterns, so mailing lists and auto-forwards never scare you out of enforcement and a real impersonation attempt raises an alert the day it appears.

Publishing a DMARC record is the easy half. Reading the reports it generates is the half that gets you safely to enforcement.
Every report is parsed as it arrives, so a broken sender surfaces the same week.
Who sends as you, and which of them fails alignment.
When Google and Yahoo started requiring this of bulk senders.
The only policy that stops spoofing, reached without breakage.
Monitored free, no card, so you can start reading reports today.
1,000 free on signup. 2,500 with a work email. Pay as you go after.
Parsed in your account only. SOC 2 · GDPR · CCPA.
Most tools reset your balance every month. Verifox sells credits that sit in your account until you spend them.
forever
1,000credits on signup
No card required
2,500 with a work email
Free includes
one time
10,000credits
$0.0059 eachSAVE 34%
Everything in Free, plus
per month
15,000credits a month
$0.0053 each
Unused credits roll over
Everything in packs, plus
One credit verifies one address; a find costs 10. All prices in USD, checkout via Stripe.
Growth leads, marketers, and engineers running real campaigns on real lists, with a verified email on every byline.

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.

We were paying ZeroBounce a four-figure monthly bill and still landing 3% bounces on cold campaigns. Switched the pipeline to Verifox, dropped to 0.4% bounces, and cut the bill by more than 90%.

Ran a 50,000-address outbound list through Verifox before our quarterly campaign. Bounces landed at 0.7%, sender reputation didn't move, replies were up 22% over last quarter.

Our SDRs were enriching from three tools and 14% of the emails were invalid before they hit the sequencer. Verifox sits in the pipeline now and the team stopped seeing 'undeliverable' replies the next week.

Other tools flag 30% of our B2B list as 'risky catch-all' and leave the call to us. Verifox returns a real verdict on those addresses, with a confidence score. We send more, we send safer.

Their MCP server let me wire email verification directly into our internal Claude agent in about ten minutes. Zero glue code. No other vendor in this space has thought about that workflow.

Bulk upload, sorted CSV back in twenty minutes, plug into our growth stack. The half-day list-hygiene project per cohort turned into something the marketing intern runs on autopilot.

We had a Gmail spam-folder problem after a bad list import. Verifox cleaned the list and the warmup ran on the same engine. Back in primary inbox in six weeks. One vendor, half the cost.

Tested Verifox at 10,000 verifications per minute on a Tuesday morning. Latency held under 400ms median, no soft failures, no rate-limit walls. The vendor we benched throttled at 2,000/min.

Verifox returns a 0-100 confidence score per address, not just a label. We thresholded at 75 for the cold sequencer, 60 for nurture, and our deliverability team finally has a knob they can tune.
Every layer of the stack carries a third-party attestation, so you can ship into regulated industries without rebuilding your compliance posture.

Independently audited to the SOC 2 Type II standard.

Built for the EU with full GDPR data-subject rights.

California opt-out, do-not-sell, plus DSAR handling.

Information security held to the ISO 27001 standard.

AI governance aligned to the new ISO 42001 standard.
An investigation into the money leaking out of your list - and the nine checks that decide whether your email is read, or never arrives at all.

57 pages, free PDF, no signup
Common questions
What teams ask between publishing p=none and daring to type p=reject: report formats, alignment mechanics, and subdomain traps.
A DMARC aggregate report is a daily XML file that mailbox providers like Gmail and Yahoo send to the rua= address published in your DMARC record. It lists every IP that sent mail claiming your domain, the message counts, and the SPF and DKIM alignment result for each batch. Verifox receives these reports, parses the XML, and resolves the IPs into named services, so you read a dashboard instead of gzipped attachments.
RUA reports are aggregate: daily per-source counts of messages with pass and fail totals, no message content. RUF reports are forensic: redacted copies of individual failing messages. In practice RUA carries nearly all the value, because most large providers, Gmail included, decline to send RUF for privacy reasons. Verifox accepts both, but every policy recommendation we make is built from your aggregate data, which arrives reliably from every major receiver.
Two weeks is the practical minimum; domains with many sending services need longer. p=none blocks nothing, and its whole job is to collect aggregate reports until every legitimate source is identified and aligned. Move when your alignment rate is stable and high, not on a calendar date; the monitor flags the moment that holds. Start with a free DMARC, DKIM, and SPF check to see which policy your domain publishes today.
Since February 2024, anyone sending 5,000 or more daily messages to Gmail or Yahoo must publish a DMARC policy of at least p=none, authenticate with both SPF and DKIM, align the visible From domain, offer one-click unsubscribe, and keep spam complaints under 0.3%. Smaller senders still need SPF or DKIM. Mail that misses the bar gets throttled or rejected, which is why DMARC monitoring stopped being optional for bulk senders.
The sp= tag sets a separate DMARC policy for subdomains; without it, subdomains inherit your p= value. It matters because attackers deliberately spoof forgotten subdomains like mail.yourdomain.com or billing.yourdomain.com, where nobody is watching. Verifox tracks every subdomain that appears in your aggregate reports and warns you when sp=, or a missing record on a delegated subdomain, leaves one of them weaker than your organizational policy.
SPF alignment compares the Return-Path domain with your visible From domain; DKIM alignment compares the d= domain in the signature. A message passes DMARC when either one passes and aligns. The practical difference is forwarding: it rewrites the Return-Path and breaks SPF, while a DKIM signature survives intact. That makes aligned DKIM the backbone of a safe p=reject. If one source keeps failing, the free DKIM tester shows whether its signature validates at all.
pct= applies your policy to only a percentage of failing mail. At p=quarantine with pct=25, a quarter of failing messages go to spam and the rest are treated as p=none. It is a throttle for nervous rollouts. Treat it as a short ramp, not a destination: a long-lived pct below 100 leaves a permanent gap spoofed mail can ride through, and some receivers do not honor the tag at all.
Yes. Monitoring is free for one domain, with unlimited aggregate reports and no card required. Signing up also grants 1,000 free credits, or 2,500 with a work email, usable across the whole platform. Additional domains run on the same pay-as-you-go credits, which never expire, and the pricing page shows rates localized for your region.
Yes. Per-source alignment rates, parsed report history, policy state, and spoofing alerts are all exposed over REST and documented in the API reference. Webhooks push new-source and failure-spike events into Slack or your own tooling, and AI agents can read the same data through the native MCP server. Most teams wire it next to email verification so hygiene and authentication share one pipeline.