Hosted DMARC

Change your DMARC policy from the dashboard, with one CNAME in DNS.

Point _dmarc at us and we serve the record. Move from p=none to quarantine to reject from your dashboard, and move back the moment a step catches real mail. Each change lands in our zone within a quarter hour, and the record's five-minute TTL carries it to receivers from there.

Create your account How monitoring works

Part of the paid plans · 14 days free, no card · Leave with one record swap

The hosted DMARC card for a domain at quarantine: the live badge, the policy, subdomain policy and percentage controls, and the history of every move. The hosted DMARC card for a domain at quarantine: the live badge, the policy, subdomain policy and percentage controls, and the history of every move.
The hosted DMARC card for a domain at quarantine. The policy, the subdomain policy and the percentage are the three controls. Every move is listed under them.
Setup

Setup is one CNAME

The CNAME proves you own the domain, sends the reports to us, and hands the record over. After it resolves, the policy moves from the page.

STEP 1

Switch to hosted

On the domain's DMARC page, press Switch to hosted DMARC. We read the record you publish today and carry its policy and tags over, with our reporting address in place of the old one. A domain with no record starts at p=none.

STEP 2

Publish one CNAME

Delete the TXT at _dmarc, then add the CNAME we give you at the same name. The TXT goes first because two answers at that name make receivers discard both.

STEP 3

Move the policy from the page

Once the CNAME resolves to us, the ramp opens. Pick the policy, the subdomain policy and the percentage, save, and the record changes in our zone.

What you get

Move the policy up or down from the same controls

Getting to p=reject takes several small steps. Moving back down is the step you take in a hurry, and it's the same control.

A warning before a risky step

Tighten the policy while your reports still show real mail failing, and the page says so before it saves. Confirm and it goes.

Rollback with no confirmation step

Drop from quarantine to none, or from reject to quarantine, and nothing asks you to confirm. Rolling back is the move that has to be fast.

Your reporting address is in the record

The record we serve carries your reporting address. Hosting the record and receiving the reports is one setup, and the CNAME is also the proof you own the domain.

A history of every change

Each change to the served record is kept with when it happened and what changed. The history sits under the controls, so the week the pass rate moved can be read against the edit that moved it.

We check the record is live every fifteen minutes

We push to our zone, then read the record back through public DNS every fifteen minutes. The badge says live only after that read succeeds, and says broken when a delegation that was live stops resolving.

The controls change three tags

The ramp writes p, sp and pct. The reporting address and every other tag stay exactly as they were.

When something fails

What an outage does to your mail

If our DNS is unreachable

Receivers find no policy at _dmarc and treat your mail the way they treat a domain with no DMARC record: it delivers. Protection and reporting pause until our zone answers again. An outage on our side costs you reports for the duration. It costs you no mail.

If your plan lapses

The record keeps serving exactly as it stands and only the controls lock. Cutting a live record over a billing event would break mail, so we don't. Upgrade and the controls unlock. Stop hosting and the page hands you the record to publish yourself.

Leaving

Stop hosting whenever you want

Press Stop hosting and the page writes out the TXT we were serving, ready to paste at _dmarc. Publish it, delete the CNAME, and the domain is self-managed again with the same policy and the same reporting address. We keep answering the old name until your DNS stops referencing it, and for twenty days after that, so a receiver that cached the CNAME still finds a policy.

Plans

Part of Pro and Team

Hosted DMARC comes with the paid plans, beside the monitoring they're built on: the Monday digest, same-day alerts, and the sender evidence behind every verdict. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, no card.

Read the full plan table

FAQ

Questions people ask first

Do I need hosted DMARC to use DomainCanary?

No. Monitoring works with a record you manage yourself: you add our reporting address to the TXT you already publish. Hosting is for a domain whose policy you'll move more than once, and would rather move from a page than through a DNS ticket.

What's the difference between hosted DMARC and DMARC monitoring?

Monitoring reads the reports receivers send about your domain. Hosting serves the record those receivers read. Monitoring works without hosting. Hosting always includes monitoring, because the record we serve carries your reporting address.

Does a CNAME at _dmarc work everywhere?

At every receiver, yes. They look up the TXT at _dmarc.yourdomain.com, and a CNAME at that name sends the lookup to the name we serve. The one rule is that nothing else can sit at a name that holds a CNAME, so the old TXT is deleted first.

How fast does a policy change reach receivers?

We push every change to our zone within fifteen minutes of the save, and the record carries a five-minute TTL. A receiver that cached the old answer reads the new one when that expires.

Can I roll back?

Yes. Moving the policy down is one save with no confirmation step. If p=quarantine starts catching a real sender, drop back to p=none and the record changes on the next push.

What happens if DomainCanary is down?

Receivers find no policy at _dmarc and deliver your mail the way they do for a domain with no DMARC record. Protection and reporting pause until our DNS answers again. Mail keeps flowing.

Which tags can I change from the page?

p, sp and pct: the policy, the subdomain policy and the percentage. The reporting address is written by us and every other tag carries over from the record you switched from.

What does it cost?

It's part of Pro and Team. Pro watches 5 domains for $19 a month and Team watches 25 for $79. Every paid feature is free for 14 days, and the trial needs no card.

Host the record, then change the policy without a DNS ticket

Each Monday digest names the week the next step is safe. With the record hosted, that step is one save on the page.

First domain free · 14 days of every paid feature · No card

  • One CNAME at _dmarc, then no more DNS edits
  • Policy, subdomain policy and percentage from the page
  • Rollback in one save, with no confirmation step
  • Fails open: mail delivers if our DNS is ever unreachable