Anyone on the internet can send email claiming to be your domain. Domain Protection shows you exactly who is doing it, and walks you to the point where receivers stop letting them.
It does that with DMARC — the standard that lets you tell Gmail, Microsoft 365 and every other mailbox provider what to do with mail that fails authentication for your domain. Publishing DMARC is easy. Getting to the point where it actually blocks anything, without blocking your own invoices and password resets on the way, is the part most organisations never finish. That journey is what this product is for.
Table of Contents:
- How it works
- Getting started
- What you will see
- The journey to enforcement
- Good to know
- Frequently asked questions
How it works
Mailbox providers already send daily reports about every message claiming to be your domain — who sent it, from which server, and whether it authenticated. Those reports are XML, they arrive from dozens of providers in slightly different dialects, and reading them by hand is nobody's job.
Domain Protection gives you a unique reporting address, you point your domain's DMARC record at it, and from then on:
- We receive and parse the reports as providers send them, and turn them into one view across every domain you monitor.
- We identify the senders. Each sending server is resolved and named where we can — your mail platform, your marketing tools, your vendors, and anything you do not recognise.
- We tell you what to change, and check each step against your own reporting before recommending it.
Getting started
1. Add your domain
Open Threat Analysis → Domain Protection, then Domain Protection Settings, and add the domain you want to monitor. You can add any domain you control — including ones that send no mail at all, which are the easiest to spoof and the easiest to protect.
2. Publish the DNS record we show you
Each domain gets its own reporting address on canidmarc.com, our dedicated reporting infrastructure. The Setup Wizard composes the exact TXT record to publish, for example:
| Type | TXT |
| Host | _dmarc.yourdomain.com |
| Value | v=DMARC1; p=none; np=reject; rua=mailto:yourtoken@au.canidmarc.com |
Copy it into your DNS provider exactly as shown. If you already publish a DMARC record, the wizard adds our address to your existing rua= list instead of replacing anything — report destinations are comma-separated, so whatever you have today keeps working.
3. That is the verification
There is no separate code to paste and no ownership form to fill in. Only whoever controls a domain's DNS can publish that record, so publishing it is the proof. We re-check DNS every 15 minutes, and the domain moves to Verified on its own — usually within the hour. Reports typically start arriving within 24 to 48 hours, because most providers send once a day.
We never change your DNS. Domain Protection reads your records and tells you what to publish. Every change is made by you, in your own zone, and can be undone by you at any time.
What you will see
Monitored Domains
One row per domain, with its current status, the policy it publishes today, how many reports have arrived and when the last one landed. Opening a domain gives you the Setup Wizard for it.
The Setup Wizard
A guided walkthrough for every email authentication record, not just DMARC:
| Record | What it does |
|---|---|
| DMARC | The policy itself. The wizard builds it from your choices and shows the record updating as you go. |
| SPF | Lists the servers allowed to send as you. We diagnose your record and name each fault — we do not rewrite it, because only you know every system that sends as you. |
| DKIM | Signs your mail so it still authenticates after forwarding. We show every signing key we can see, how we found it, and which are actually in use. |
| MTA-STS | Requires encryption on mail sent to you. The wizard composes both halves — the DNS record and the policy file. |
| TLS-RPT | Asks other servers to report when they cannot reach you securely. |
| BIMI | Displays your logo beside authenticated mail. Available once your domain enforces DMARC. |
Analytics View
Your reported email volume against how much of it authenticated, viewable over the last 30 days, 12 months or your full history. Below it, every sending source we have seen — its address, who operates it, how much it sent and what proportion passed DMARC. This is the table that tells you which of your own systems are misconfigured, and which senders are not yours at all.
Recommendations
Each domain carries a ranked list of what to do next, drawn from your own reporting rather than a generic checklist. Anything you have handled or decided against can be dismissed, and it will come back only if the underlying issue recurs.
Notifications
Email alerts when something changes on a monitored domain — a policy weakened, reporting stopped, a new problem found. You choose which severities are worth an email; Critical and High are on by default.
The journey to enforcement
DMARC has three policies, and the whole point is to move through them safely:
| Policy | What receivers do |
|---|---|
p=none |
Nothing is blocked. Reports are sent. This is where every domain starts. |
p=quarantine |
Mail that fails authentication goes to spam. |
p=reject |
Mail that fails is refused outright and never arrives. |
Moving up too early is how organisations lose real mail, so we will not recommend a step until your own reports support it. Before suggesting quarantine we look for:
- at least 21 days of reporting history, so seasonal and monthly senders have had a chance to appear;
- mail observed on at least 14 separate days, so the picture is not one busy afternoon;
- at least 100 messages seen by recognised reporters, so the pass rate means something.
After quarantine, we look for a further 14 days at that policy with no new problems before suggesting reject. When a step is not yet advisable, the product tells you which specific check has not cleared rather than simply saying "not yet" — and you can always move faster by hand if you know your estate.
A domain that sends no mail is the quick win. If a domain genuinely sends nothing, it can go straight to p=reject with an SPF record of v=spf1 -all. There is no legitimate mail to break, and leaving it unprotected is an open invitation to spoof it.
Good to know
- Up to 50 domains are included, sending or parked, with no limit on email volume.
- Reports are retained for 13 months, so year-on-year comparisons are available once you have the history.
- One account per domain. A domain can be monitored by one account at a time, and that claim belongs to whoever proves control of the DNS — not to whoever added it first.
- Pausing keeps your history. Pausing a domain parks it on your dashboards while ingestion continues, so resuming loses nothing. Removing it stops ingestion — remember to take our address out of your DNS record too.
- Domain Protection requires an Enterprise subscription.
Frequently asked questions
Will any of this change how my email is delivered?
No. Adding a domain changes nothing on its own, and the record we ask you to publish starts at p=none, which asks receivers to report but tells them to change nothing. Delivery only changes when you decide to move to quarantine or reject, and that is a DNS edit you make yourself.
How long until I see data?
The domain verifies within about 15 minutes of you publishing the record. Reports take longer, because most mailbox providers send once a day — expect the first ones within 24 to 48 hours, and a useful picture after a few days.
I already use another DMARC provider. Do I have to switch?
No. A DMARC record can name several report destinations, separated by commas, and each one receives its own copy. The Setup Wizard adds our address to your existing list rather than replacing it, so your current tooling keeps working exactly as it does now.
Why does a sending source say "Unknown"?
We identify senders from the reverse DNS of each sending server, matched against a catalogue of known providers. When a server's operator is not in that catalogue we show you the evidence we have — the reverse DNS name and the network it belongs to — rather than guessing at a name. A wrong name is worse than none, because you might authorise a sender on the strength of it. If you recognise a source we have not named, tell us and we will add it.
Why am I seeing mail I did not send?
That is the point of DMARC reporting, and it is normal. Some of it is spoofing. A lot of it is legitimate mail you had forgotten about — a marketing platform, a ticketing system, an old server — and some is your own mail being forwarded, which breaks SPF by design. The Analytics View exists to help you tell the three apart before you enforce anything.
Why can I not move to quarantine or reject yet?
Because your reports do not support it yet, and moving early is how organisations lose real mail. We look for 21 days of history, mail observed on at least 14 separate days, and at least 100 messages seen by recognised reporters. The product always names the specific check that has not cleared rather than just saying "not yet" — and if you know your estate well, nothing stops you moving faster by hand.
Do I have to set up SPF, DKIM and the rest?
Not to get started. DMARC alone gives you reporting, which is where all the value begins. SPF and DKIM matter when you want to reach enforcement without losing mail — particularly DKIM, which is the only one that survives forwarding. The Setup Wizard covers each of them when you are ready.
Can another customer see my report data?
No. Every domain gets its own private reporting address, and reports are routed to your account by that address rather than by the domain named in the report. Report data is stored per account and every screen reads only your own. A domain can also only be verified on one account at a time.
Someone else has already verified my domain. What now?
That message means our address is currently published in that domain's DNS pointing at another account — which is how ownership is proven. If you control the domain's DNS and did not authorise this, contact support and we will resolve it.
What happens if I remove a domain?
Report ingestion stops immediately and the reporting address is retired. Remove our address from your DNS record as well, or providers will keep trying to deliver to an address that no longer accepts anything. If you only want a domain off your dashboards, pause it instead — pausing keeps the history and keeps ingesting.
How far back does the data go?
Reports are retained for 13 months, so once you have the history you can compare against the same period last year. Nothing older than that is kept.
If a sending source appears that you do not recognise, or a recommendation is not clear, contact support and we will take a look with you.
Comments
0 comments
Please sign in to leave a comment.