Tool

DMARC monitoring for sender inventory and enforcement.

Collect aggregate reports, label known and unknown senders, inspect SPF and DKIM alignment, and move toward enforcement with evidence instead of guesswork.

RUA

aggregate reports

TLS-RPT

transport reports

Alerts

policy drift

DMARC enforcement starts with sender inventory

Moving from p=none to quarantine or reject is risky when you do not know every service sending as your domain. WillItInbox turns aggregate reports into source labels, alignment evidence, disposition trends, and owner-ready follow-up.

  • Identify known and unknown senders before tightening policy.
  • Separate SPF alignment, DKIM alignment, and receiver disposition.
  • Use domain monitoring for SPF, DKIM, DMARC, MX, TLS, PTR, and blocklist drift.
  • Use the checker for publication; use monitoring for evidence over time.

Turn reports into an enforcement decision

A DMARC record checker confirms publication. Monitoring answers the harder questions over time: which systems are sending, whether they align, what receivers did, and whether policy can safely move toward enforcement.

Check publication

Use the free DMARC checker to inspect effective policy, inheritance, testing mode, and reporting tags.

Review the rollout

Follow the DMARC rollout guide before tightening policy.

Inspect a diagnosis

See how SPF, DKIM, alignment, and DMARC evidence become a remediation plan.

Recommended rollout

Treat DMARC as a measured rollout. Publish reporting, read the evidence, fix legitimate senders, then move policy in controlled steps.

StagePolicyWhat to prove
Discoveryp=noneAll legitimate senders are visible and labeled.
Containmentp=quarantine with t=yAligned mail keeps passing while unknown senders shrink.
Enforcementp=quarantine without tLegitimate senders remain aligned across representative reporting cycles.

Authentication owner

DMARC monitoring turns authentication records into sender inventory

A DMARC checker can confirm a record exists. Monitoring answers the operating question: which services are sending as the domain, whether SPF or DKIM aligns with the visible From domain, and whether enforcement would block legitimate mail.

Aggregate reports

Use RUA reports to see source IPs, header From domains, SPF/DKIM outcomes, alignment, counts, and receiver disposition.

Unknown senders

Separate forgotten SaaS tools, ESP migrations, forwarders, and abuse before tightening policy.

Policy rollout

Move from p=none to quarantine or reject only after legitimate senders are visible and aligned.

Alignment matrix

SPF pass, DKIM pass, and DMARC pass are not the same result

DMARC requires alignment with the visible From domain. WillItInbox should explain both raw authentication and aligned authentication so teams fix the right identity, not just any passing record.

SignalWhat passesWhat DMARC needsCommon fix
SPFEnvelope sender / Return-Path is authorized.Envelope domain aligns with visible From domain.Configure a custom bounce domain or aligned return path.
DKIMA signature verifies for the d= domain.DKIM d= domain aligns with visible From domain.Sign with the From domain or an aligned organizational domain.
DMARCAt least aligned SPF or aligned DKIM passes.Policy and reporting are published for the From domain.Fix sender configuration before increasing enforcement.

Checker vs monitoring

Use free diagnostics for publication; use monitoring for decisions

The free tools are intentionally narrow. They are excellent for checking publication quickly, while the monitoring workflow records whether real senders align over time.

QuestionBest first pageWhy
Is my DMARC record published?/tools/dmarc-checkerIt inspects policy, subdomain policy, percentage, and reporting tags.
Is my SPF record structurally risky?/tools/spf-checkerIt checks the visible SPF record and lookup-producing mechanisms.
Which services send as my domain?/tools/dmarc-monitoringAggregate reports expose source IPs, alignment, volume, and dispositions.
Can I move to quarantine or reject?/blog/dmarc-rollout-none-to-rejectPolicy changes need sustained aligned legitimate volume and low unknown-source risk.

Readiness checklist

Do not increase enforcement until these are true

DMARC failures can break invoices, password resets, product emails, marketing sends, and support workflows. The checklist should be boring on purpose.

  • Every legitimate sender is labeled with an owner and business purpose.
  • High-volume senders have aligned SPF or aligned DKIM.
  • Unknown-source volume is explained, blocked intentionally, or acceptably small.
  • Aggregate report ingestion covers multiple representative reporting cycles.
  • Rollback instructions are documented before moving to quarantine or reject.

FAQ

Should I jump directly to p=reject?

No. Start with reporting, label senders, fix alignment gaps, then test quarantine with t=y. RFC 9989 cautions general-purpose domains against reject unless their interoperability analysis supports it.

Does DMARC monitoring guarantee inbox placement?

No. It identifies authentication, sender-inventory, and policy risk. Inbox placement still depends on reputation, engagement, recipient history, provider behavior, content, and timing.

Does DMARC monitoring guarantee inbox placement?

No. DMARC monitoring identifies sender inventory, alignment, policy, and authentication risk. Inbox placement also depends on reputation, engagement, recipient history, content, and provider behavior.

Is there a DKIM checker?

Yes. Use the free DKIM checker to probe common selectors and validate published keys, then use DMARC monitoring to watch signing-domain alignment over time.