From sign-up to p=reject
The whole rollout, in the order you will do it. Each article covers one step: what to click, what to publish, and how to tell it worked.
The rollout at a glance
- Day 0 Set up Create an account, add your domain and publish its DMARC and SPF records. Nothing about how your mail is handled changes.
- Day 1โ2 First report Mail receivers send aggregate reports once a day. The first usually lands within 48 hours.
- Day 14 Quarantine review At least two weeks of reports covers your weekly senders. If they all pass, test p=quarantine.
- Day 30 Enforce quarantine Thirty days covers the monthly senders โ invoicing, payroll, statements. Then drop t=y and enforce quarantine.
- Day 60 on Reject After a month of quarantine enforcing cleanly, with every sender aligned, test p=reject for a week, then enforce it.
Getting started
Create an account and choose where to start.
- 01 Create your account Sign up with your work email, confirm the address, and set up the organisation your domains, reports and people will belong to.
- 02 Choose a plan Every organisation starts on Free, with no card. What each limit counts, how to move to a paid plan, and what happens when you change plan later.
- 03 Set up two-factor authentication Add a code from an authenticator app to every sign-in, save your backup codes, add a passkey, and know what to do if you lose your phone.
Your first domain
Add a domain, publish its DMARC and SPF records and wait for the first report.
- 04 Add your first domain Which domain to start with, how to add it on the Domains page, and how groups and tags keep a long list of domains manageable.
- 05 Publish the DNS records The setup wizard's steps, hosted or self-managed records, where to add them, and sharing the records with whoever edits your DNS.
- 06 Your report addresses The three addresses receivers send your organisation's DMARC, failure and TLS reports to, why one address serves every domain, and how to add it to a record.
- 07 Check the records are in place How the DNS records tab shows whether each record is published, what each status means, how often we check, and where its history is kept.
- 08 Get your first report When the first DMARC reports arrive, where they show up, and what the organisation overview and the domain's Overview tab tell you on day one.
Moving to enforcement
Work through your senders, then tighten the policy when the evidence says it is safe.
- 09 Identify your sending sources Between the first report and day 14, work through the servers sending as your domain. Fix the ones that are yours and leave the rest to the policy.
- 10 The 14-day review: moving to p=quarantine When the adviser says to test p=quarantine (14 days of reports) and enforce it (30 days), exactly what it checks, and how to make each change.
- 11 The 30-day review: moving to p=reject Reject waits for 30 days of reports, 98% passing and a month at enforced quarantine. What the adviser checks, and how to take the final step safely.
- 12 Staying at p=reject Enforcement isn't the end of monitoring: the alerts that matter at p=reject, the adviser board, and what to do when you add a new sending service.
- 13 Hosted records Point a CNAME or an include at DMARCLoop once, then change DMARC, SPF, TLS-RPT, DKIM and BIMI from the app, with every version kept and one-click rollback.
- 14 SPF and the ten-lookup limit Why an SPF record stops working as you add senders, how DMARCLoop counts and alerts on the lookups, and how hosted SPF flattening keeps you under ten.
- 15 Lock down a parked domain A domain that sends no mail can still be spoofed. What the setup wizard's lockdown publishes, the two records you add yourself, and how to check it.
Reports
What a domain's data shows, failure reports, MTA-STS, DKIM and BIMI, and exports.
- 16 Read a domain's DMARC data What a domain's Overview and Timeline tabs show, what the numbers mean, and why a high pass rate is not the same as a low spoofing rate.
- 17 Failure reports What DMARC failure (ruf) reports are, the little DMARCLoop keeps from each, how long it keeps them, and who can see them on the Mail security tab.
- 18 MTA-STS and TLS reports How DMARCLoop checks your MTA-STS policy every day, collects the TLS reports senders send about mail arriving at your domain, and the order to publish them in.
- 19 DKIM keys and BIMI How the Mail security tab checks every DKIM selector daily, when to rotate a key, how to host DKIM, and how to publish a BIMI logo once you enforce.
- 20 Exports and scheduled reports Download the domains sheet, a branded PDF report and the DNS records sheet, and email them weekly or monthly to people who can read reports.
Your account
People and roles, alerts and channels, billing, the audit log, the API, your data and support.
- 21 Invite people and set their roles Invite colleagues from People, choose what each role can do, and change or remove people and invitations. For MSPs, which clients each person sees.
- 22 Notifications and alerts Every alert DMARCLoop sends and when, who receives it, turning kinds off for yourself, the digest, and the getting-started emails.
- 23 Alert channels and webhooks Send alerts to Slack, Microsoft Teams, a signed webhook or a ConnectWise PSA board, choose webhook events, check a channel's health, and verify signatures.
- 24 Manage billing and invoices Plan and billing shows your plan, its status and your usage, changes the plan and add-ons, and opens Stripe for your card, invoices and cancelling.
- 25 The audit log and the email log The audit log records every change in your organisation, who made it and when, including API keys and our support staff. The email log lists the mail sent.
- 26 Use the API Create an API key with a role, call the DMARCLoop API with it, find the OpenAPI reference, and know the rate limit and what a key can reach.
- 27 Export all your data An owner can download everything the organisation holds as one zip, settings, people, domains, record history, alerts, the audit log and every report.
- 28 Delete your account How an owner deletes an organisation, what stops at once, the 30 days in which it can still be cancelled or exported, and what is deleted after.
- 29 Get help from support Send a support request from inside the app, with your organisation, role and plan attached, and follow your requests until they're answered.
- 30 Service status The public status page shows whether the dashboard, report processing, hosted DNS and notifications are working, and the history of past incidents.
For MSPs
Clients, bulk import, reporting to your customers, and white-label.
- 31 Clients, domains and who sees what How an MSP organisation holds one client organisation per customer, where their domains live, the client board, and which clients each of your people can see.
- 32 Import domains in bulk Add up to 200 domains at once from a CSV, for one organisation or many clients, see what every row will do first, then download the records each one needs.
- 33 Reports for your clients The per-client digest, a PDF report for each client under your brand, scheduled exports, and the per-client usage sheet for re-billing.
- 34 White-label Give your clients your own product name, logo, app address, sending domain and report domain, and see what they use until each part is set up.
Troubleshooting
When something has not happened that should have.
Looking for background rather than steps? The FAQ explains alignment, DMARCbis and sending on behalf of other domains, and the free tools check any domain's records without an account.