Change your DMARC policy from the dashboard, with one CNAME in DNS.
Point _dmarc at us and we serve the record. Move from
p=none to quarantine to reject from your dashboard, and move back the
moment a step catches real mail. Each change lands in our zone within a quarter hour,
and the record's five-minute TTL carries it to receivers from there.
Create your account How monitoring works
Part of the paid plans · 14 days free, no card · Leave with one record swap
Setup is one CNAME
The CNAME proves you own the domain, sends the reports to us, and hands the record over. After it resolves, the policy moves from the page.
Switch to hosted
On the domain's DMARC page, press Switch to hosted DMARC. We read
the record you publish today and carry its policy and tags over, with our reporting
address in place of the old one. A domain with no record starts at
p=none.
Publish one CNAME
Delete the TXT at _dmarc, then add the CNAME we give you at
the same name. The TXT goes first because two answers at that name make receivers
discard both.
Move the policy from the page
Once the CNAME resolves to us, the ramp opens. Pick the policy, the subdomain policy and the percentage, save, and the record changes in our zone.
Move the policy up or down from the same controls
Getting to p=reject takes several small steps. Moving back
down is the step you take in a hurry, and it's the same control.
A warning before a risky step
Tighten the policy while your reports still show real mail failing, and the page says so before it saves. Confirm and it goes.
Rollback with no confirmation step
Drop from quarantine to none, or from reject to quarantine, and nothing asks you to confirm. Rolling back is the move that has to be fast.
Your reporting address is in the record
The record we serve carries your reporting address. Hosting the record and receiving the reports is one setup, and the CNAME is also the proof you own the domain.
A history of every change
Each change to the served record is kept with when it happened and what changed. The history sits under the controls, so the week the pass rate moved can be read against the edit that moved it.
We check the record is live every fifteen minutes
We push to our zone, then read the record back through public DNS every fifteen minutes. The badge says live only after that read succeeds, and says broken when a delegation that was live stops resolving.
The controls change three tags
The ramp writes p, sp and pct.
The reporting address and every other tag stay exactly as they were.
What an outage does to your mail
If our DNS is unreachable
Receivers find no policy at _dmarc and treat your mail the way they
treat a domain with no DMARC record: it delivers. Protection and reporting pause
until our zone answers again. An outage on our side costs you reports for the
duration. It costs you no mail.
If your plan lapses
The record keeps serving exactly as it stands and only the controls lock. Cutting a live record over a billing event would break mail, so we don't. Upgrade and the controls unlock. Stop hosting and the page hands you the record to publish yourself.
Stop hosting whenever you want
Press Stop hosting and the page writes out the TXT we were serving, ready to
paste at _dmarc. Publish it, delete the CNAME, and the domain is
self-managed again with the same policy and the same reporting address. We keep
answering the old name until your DNS stops referencing it, and for twenty days after
that, so a receiver that cached the CNAME still finds a policy.
Part of Pro and Team
Hosted DMARC comes with the paid plans, beside the monitoring they're built on: the Monday digest, same-day alerts, and the sender evidence behind every verdict. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, no card.
Where to go next
Questions people ask first
Do I need hosted DMARC to use DomainCanary?
No. Monitoring works with a record you manage yourself: you add our reporting address to the TXT you already publish. Hosting is for a domain whose policy you'll move more than once, and would rather move from a page than through a DNS ticket.
What's the difference between hosted DMARC and DMARC monitoring?
Monitoring reads the reports receivers send about your domain. Hosting serves the record those receivers read. Monitoring works without hosting. Hosting always includes monitoring, because the record we serve carries your reporting address.
Does a CNAME at _dmarc work everywhere?
At every receiver, yes. They look up the TXT at _dmarc.yourdomain.com, and a CNAME at that name sends the lookup to the name we serve. The one rule is that nothing else can sit at a name that holds a CNAME, so the old TXT is deleted first.
How fast does a policy change reach receivers?
We push every change to our zone within fifteen minutes of the save, and the record carries a five-minute TTL. A receiver that cached the old answer reads the new one when that expires.
Can I roll back?
Yes. Moving the policy down is one save with no confirmation step. If p=quarantine starts catching a real sender, drop back to p=none and the record changes on the next push.
What happens if DomainCanary is down?
Receivers find no policy at _dmarc and deliver your mail the way they do for a domain with no DMARC record. Protection and reporting pause until our DNS answers again. Mail keeps flowing.
Which tags can I change from the page?
p, sp and pct: the policy, the subdomain policy and the percentage. The reporting address is written by us and every other tag carries over from the record you switched from.
What does it cost?
It's part of Pro and Team. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, and the trial needs no card.
Host the record, then change the policy without a DNS ticket
Each Monday digest names the week the next step is safe. With the record hosted, that step is one save on the page.
First domain free · 14 days of every paid feature · No card
- One CNAME at _dmarc, then no more DNS edits
- Policy, subdomain policy and percentage from the page
- Rollback in one save, with no confirmation step
- Fails open: mail delivers if our DNS is ever unreachable