DMARC record monitoring

DMARC monitoring for the record itself: know when it weakens.

DMARC monitoring usually means one of two jobs: reading the aggregate reports receivers send you, or watching the DNS record that sets your policy. Attack Surface Scan does the second. It checks your DMARC, SPF, MTA-STS and TLS-RPT records on every scheduled scan and alerts the moment one is removed, loosened or rewritten, with the before and after inline.

No card required to start. Plans from $25/month; first scan in about a minute.

Why DMARC record drift matters

A DMARC policy is only as strong as the TXT record published today. Records drift through ordinary DNS work, and nothing in your mail flow tells you when they do.

p=reject, quietly undone

A DNS migration, a registrar move or a vendor onboarding rewrites the zone, and the _dmarc record comes back as p=none, or not at all. Mail keeps flowing, so nobody notices spoofing has stopped being blocked.

SPF breaks as includes pile up

Every new email vendor adds an include:. Past ten DNS lookups, receivers treat SPF as a permanent error and stop honoring it, while your own mail still looks fine from the inside.

Reports going to a dead mailbox

The rua= address points at a vendor you left or an inbox nobody reads. Your DMARC reporting has been silently switched off, and the record still looks valid.

Inbound TLS protection lapses

An MTA-STS policy that drops from enforce to testing, or a policy file that stops serving, reopens the door to downgrading delivery to plaintext. It rarely gets a ticket.

How Attack Surface Scan does DMARC monitoring

Every scheduled scan re-reads your email authentication records and compares them with the last scan, so a change is an alert with evidence rather than a surprise months later.

Every SPF and DMARC change, diffed

Any edit to the SPF or DMARC record raises a change with the old and new record side by side: a policy moved from reject to none, a new include, a changed rua address. A removed record is flagged at high importance.

Weak policy called out as findings

A missing SPF or DMARC record, DMARC parked at p=none, and SPF ending in soft fail each appear as findings with the specific fix, so the gap is on the list even if it never changed.

MTA-STS and TLS-RPT too

For domains that receive mail, the MTA-STS DNS record and policy file are checked together, mode changes are alerted (enforce dropping to testing is high importance), MX hosts the policy doesn't cover are flagged, and a missing TLS-RPT record is reported.

Alerts where you already look

Critical changes go out immediately by email, Slack or webhook; the rest arrive in a weekly digest. Need the lookup count right now? The free SPF & DMARC checker follows the include chain against the limit of 10.

What this is not: DMARC report analysis

No aggregate or forensic report processing

Attack Surface Scan does not ingest, parse or chart DMARC aggregate (rua) or forensic (ruf) reports. If you need to see which sources send as your domain and whether they pass alignment, you want a dedicated DMARC report processor. DMARC report tools compared →

The two jobs fit together

A report processor tells you whether your mail passes; record monitoring tells you whether the policy you rely on is still published. Many teams run both, and point rua at the report tool while Attack Surface Scan watches the record. SPF, DKIM and DMARC explained →

Common questions

What is a DMARC monitoring service?

The term covers two kinds of tool. DMARC report services collect the aggregate reports that receivers email to your rua address and show who sends as your domain. DMARC record monitoring, which is what Attack Surface Scan does, watches the published DMARC, SPF and MTA-STS records and alerts when they change or weaken. They answer different questions.

Is there free DMARC monitoring?

For a one-off check, yes: the free SPF & DMARC checker grades your records and counts SPF lookups in your browser. Continuous record monitoring is part of Attack Surface Scan's paid plans, from $25/month with a 7-day free trial and no card. For report processing, several dedicated tools have free tiers; see the DMARC tools comparison.

Which DMARC tools read aggregate reports?

Dedicated DMARC report platforms do; Attack Surface Scan does not. It monitors the records themselves. The comparison of DMARC monitoring tools covers the report processors, and Attack Surface Scan sits alongside them.

What changes does the DMARC monitor alert on?

Any change to the SPF or DMARC record (policy, rua address, includes, or the record disappearing), MTA-STS mode changes or removal, plus standing findings for a missing record, p=none, soft-fail SPF, an unreachable MTA-STS policy file and a missing TLS-RPT record.

Put your DMARC record under watch.

Verify your domain and every email authentication record is checked on the first scan.

Start your 7-day trial

No card required to start. Cancel any time.