Your account Step 22 of 35

Notifications and alerts

Every alert DMARCLoop sends and when, who receives it, turning kinds off for yourself, the digest, and the getting-started emails.

Updated

DMARCLoop tells you when something about a domain changes and a person should act. Each alert is sent once, when its condition starts, by email to the people who can act on it and to the organisation’s alert channels. Between alerts, a digest summarises every domain.

The Alerts page

Alerts, in the left sidebar, has three parts:

  • Happening now: every condition currently true, with its domain. Nothing needs attention. when there are none.
  • Channels: Slack, Microsoft Teams, webhooks and ConnectWise PSA; see Alert channels and webhooks.
  • Sent: every alert sent, when, and how many people and channels it reached.

The Alerts page: what’s happening now, and the channels

Every alert

Alert Sent when
DMARC record missing A DMARC record that was published is no longer there.
DMARC record invalid The DMARC record no longer parses, so receivers ignore it.
Reports no longer sent to us The DMARC record is present but no longer sends reports to us.
Hosted DNS delegation broken A CNAME or include that delegates a record to us no longer points at us.
DNS record changed A record you manage yourself no longer matches what it should be.
Ready to tighten policy The adviser thinks a domain can safely move to a stricter policy.
Policy step blocked A domain has enough evidence for its next step, but a sending source keeps failing.
Mail being blocked An enforcing domain has legitimate-looking mail failing DMARC.
Policy loosened The published DMARC policy was loosened.
Reports stopped A domain that was receiving DMARC reports has had none for seven days.
New sending source A source not seen before sent meaningful volume as the domain: 50 messages in its first two days.
Compliance dropped The share of mail passing DMARC fell by five points or more, week on week (with at least 100 messages each week).
Volume spike A day’s mail was more than three times the usual volume (the median of the previous 14 days), and at least 500 messages.
SPF lookup limit exceeded The SPF record needs more than ten DNS lookups, so receivers treat it as failing.
SPF record invalid The SPF record doesn’t parse, or the domain publishes more than one.
Hosted SPF not updating The flattened SPF record we serve couldn’t be rebuilt three times in a row.
DKIM key weak A DKIM selector publishes an RSA key under 1024 bits, which receivers reject.
MTA-STS policy broken The MTA-STS policy can’t be fetched, doesn’t parse, or doesn’t cover the MX hosts.
BIMI broken The BIMI logo or its mark certificate fails a check, or the certificate expires within 30 days.
Alert channel failing A Slack, Teams, webhook or PSA channel has rejected five alerts in a row.

The adviser and the report checks run once a day; DNS records are checked every six hours. A condition that stays true isn’t sent again; one that clears and comes back is.

Who receives them

Alerts are emailed to the Owners, Admins and Analysts who can act on the domain. In an MSP, that includes the MSP’s people who can see that client. Read-only and Billing members don’t receive alerts.

My notifications

My notifications, in the left sidebar, is your own choice for this organisation. Changing them changes nothing for anyone else.

  • Alerts: each kind with On or Off, and Turn off or Turn on. Turning a kind off stops it reaching you by email; channels still get every kind.
  • Digest: Send me the Default, Weekly, on Mondays, Monthly, on the 1st, or Off. The default is weekly for owners, admins and analysts who see the whole organisation, and off otherwise.
  • Getting started emails: On unless you choose Turn off. See below.

My notifications: the digest and the alerts you receive

The digest

The digest summarises every domain: its volume and pass rate, where it is on the way to p=reject, which domains are ready to tighten, and what needs attention. Every digest email has a link to unsubscribe from it.

In an MSP, How you receive it chooses between One email for the whole account and One email per client.

Getting started emails

A few emails help a new account and each new domain along. Each is sent once.

Email Sent when To
Welcome You create an organisation, within a few minutes. You
Welcome (member) You accept an invitation to an organisation. You
No domain yet An organisation has no domain three days after it was created. Owners and admins
Setup reminder A domain’s DMARC record still isn’t in place, and no report has arrived, 2, 7 and 21 days after it was added. The 21-day one is the last. Owners and admins
First report received The first aggregate report for a domain arrives (we look every hour). Owners and admins
Enforcing at p=reject The adviser sees a domain publishing p=reject and receivers enforcing it. Owners and admins

A setup reminder stops as soon as the domain’s DMARC record is in place or a report arrives, and links to the domain’s setup, where you can send the records to whoever edits your DNS. In an MSP, the MSP’s owners and admins receive them for each client too. Nothing is sent about an organisation that is scheduled for deletion.

Turn them off under My notifications, or with the Unsubscribe link at the foot of each one. Either turns them off for you in that organisation only.

Next

Alert channels and webhooks.

Stuck? Reply to any email DMARCLoop sends, or contact us — a person reads it.