Your domain name is
the keys to your kingdom.
You registered your name for a reason. So, two things worth knowing: anyone on the internet can send email signed with it — and whether your own messages reach inboxes or rot in spam folders depends on proving they're really yours. We'll read your records, explain them in plain English, and tell you exactly what to fix.
Two reasons to care,
even if you've never heard of DMARC.
Anyone can sign your name.
Email's oldest flaw: the From line is just text. Anyone, anywhere, can put your domain on a message — fake invoices to your customers, password resets to your team — and it arrives wearing your good name. SPF and DKIM are the fix: a list of couriers allowed to carry your letters, and a wax seal that proves a message left your hand. DMARC is your standing decree telling Gmail, Outlook, and the rest what to do when mail shows up in your name without the seal: deliver it, quarantine it, or burn it.
Your reputation decides where your mail lands.
Every major mailbox keeps score on your domain. Messages that prove their origin build that reputation; messages that can't, erode it — and quietly steer your real mail toward spam folders. Since 2024, Google and Yahoo flat-out require authentication from anyone sending in volume. If your invoices, newsletters, or quotes keep landing in spam, this is very often why — and it's fixable.
Built for people who own a domain,
not a compliance budget.
Grade what's there now. Translate the strange acronyms into language you can actually act on. Then keep an eye on things — quietly — until something changes.
A quick verdict
Type a domain. We read your SPF, DKIM, DMARC, MX, BIMI and transport policy and hand back a Report Card grade with the weak spots highlighted.
The arcane, translated
Most of this stuff was designed by committee in 1998. Our AI scribe unpacks every record and chain, names the actual services sending as you, and explains it the way you wish someone had the first time.
Quiet watch
Add one line we generate for your domain. Daily reports from Google, Yahoo, Microsoft, and the rest start flowing in. We read them so you don't have to — and tell you when something changes.
Not a wall of checkmarks.
An actual diagnosis.
Every other checker hands you a row of red ✗s and a shrug. Ours reads the whole setup — the records, the services behind them, how they fit together — and writes you a verdict in plain English. As far as we can tell, no other tool, free or enterprise, does anything like it.
Read the full report on theonion.com→Your DMARC policy is set to
p=quarantine, which tells receivers to put unauthorized mail into the spam folder. However, thepct=50flag means this only applies to half of the failing messages; the other half are delivered normally. This is a common setting during a rollout to ensure nothing breaks, but for an established domain, it's like locking only every other door in the building.Monitoring is in a good place: you're sending reports to DMARC Digests, a recognized processing service. However, you're also carbon-copying
itservices@theonion.com. Unless someone on that team enjoys manually parsing thousands of daily XML attachments (a rare hobby), that address is likely just a graveyard for automated noise.
Add one line.
We'll handle the rest.
Every major mail provider — Google, Yahoo, Microsoft, Mail.ru, Mimecast, Proofpoint — already produces daily DMARC reports for your domain. They just go wherever you tell them. Point them at the address we generate for you, and we read every one as it arrives. You hear from us only when something actually deserves your attention.
v=DMARC1; p=none; rua=mailto:rua+your-token@dmarc.quest;