DMARC record monitoring
DMARC monitoring for the record itself: know when it weakens.
DMARC monitoring usually means one of two jobs: reading the aggregate reports receivers send you, or watching the DNS record that sets your policy. Attack Surface Scan does the second. It checks your DMARC, SPF, MTA-STS and TLS-RPT records on every scheduled scan and alerts the moment one is removed, loosened or rewritten, with the before and after inline.
No card required to start. Plans from $25/month; first scan in about a minute.
Why DMARC record drift matters
A DMARC policy is only as strong as the TXT record published today. Records drift through ordinary DNS work, and nothing in your mail flow tells you when they do.
p=reject, quietly undone
A DNS migration, a registrar move or a vendor onboarding rewrites the zone, and the
_dmarc record comes back as p=none, or not at all. Mail keeps
flowing, so nobody notices spoofing has stopped being blocked.
SPF breaks as includes pile up
Every new email vendor adds an include:. Past ten DNS lookups, receivers
treat SPF as a permanent error and stop honoring it, while your own mail still looks
fine from the inside.
Reports going to a dead mailbox
The rua= address points at a vendor you left or an inbox nobody reads. Your
DMARC reporting has been silently switched off, and the record still looks valid.
Inbound TLS protection lapses
An MTA-STS policy that drops from enforce to testing, or a policy file that stops serving, reopens the door to downgrading delivery to plaintext. It rarely gets a ticket.
How Attack Surface Scan does DMARC monitoring
Every scheduled scan re-reads your email authentication records and compares them with the last scan, so a change is an alert with evidence rather than a surprise months later.
Every SPF and DMARC change, diffed
Any edit to the SPF or DMARC record raises a change with the old and new record side by
side: a policy moved from reject to none, a new include, a changed rua
address. A removed record is flagged at high importance.
Weak policy called out as findings
A missing SPF or DMARC record, DMARC parked at p=none, and SPF ending in
soft fail each appear as findings with the specific fix, so the gap is on the list even
if it never changed.
MTA-STS and TLS-RPT too
For domains that receive mail, the MTA-STS DNS record and policy file are checked together, mode changes are alerted (enforce dropping to testing is high importance), MX hosts the policy doesn't cover are flagged, and a missing TLS-RPT record is reported.
Alerts where you already look
Critical changes go out immediately by email, Slack or webhook; the rest arrive in a weekly digest. Need the lookup count right now? The free SPF & DMARC checker follows the include chain against the limit of 10.
What this is not: DMARC report analysis
No aggregate or forensic report processing
Attack Surface Scan does not ingest, parse or chart DMARC aggregate (rua) or
forensic (ruf) reports. If you need to see which sources send as your domain
and whether they pass alignment, you want a dedicated DMARC report processor.
DMARC report tools compared →
The two jobs fit together
A report processor tells you whether your mail passes; record monitoring tells you
whether the policy you rely on is still published. Many teams run both, and point
rua at the report tool while Attack Surface Scan watches the record.
SPF, DKIM and DMARC explained →
Common questions
What is a DMARC monitoring service?
The term covers two kinds of tool. DMARC report services collect the aggregate reports that
receivers email to your rua address and show who sends as your domain. DMARC
record monitoring, which is what Attack Surface Scan does, watches the published DMARC, SPF
and MTA-STS records and alerts when they change or weaken. They answer different questions.
Is there free DMARC monitoring?
For a one-off check, yes: the free SPF & DMARC checker grades your records and counts SPF lookups in your browser. Continuous record monitoring is part of Attack Surface Scan's paid plans, from $25/month with a 7-day free trial and no card. For report processing, several dedicated tools have free tiers; see the DMARC tools comparison.
Which DMARC tools read aggregate reports?
Dedicated DMARC report platforms do; Attack Surface Scan does not. It monitors the records themselves. The comparison of DMARC monitoring tools covers the report processors, and Attack Surface Scan sits alongside them.
What changes does the DMARC monitor alert on?
Any change to the SPF or DMARC record (policy, rua address, includes, or the
record disappearing), MTA-STS mode changes or removal, plus standing findings for a missing
record, p=none, soft-fail SPF, an unreachable MTA-STS policy file and a missing
TLS-RPT record.
Put your DMARC record under watch.
Verify your domain and every email authentication record is checked on the first scan.
Start your 7-day trialNo card required to start. Cancel any time.