Documentation

Learn how to integrate and use DDMARC

Docs/Alerts/Custom Rules
10 minutesPlus+

Custom Alert Rules

Build custom alert rules to monitor what matters most to you. Configure metrics, thresholds, and notification channels for precise alerting.

Rule Builder

Each alert rule consists of three parts:

1

Metric

What to monitor (pass rate, failures, volume, etc.)

2

Condition

When to trigger (threshold, comparison, change)

3

Action

What to do (notify, group, snooze options)

Example Rule

WhenPass Rateisless than90%for domainexample.com→ notify viaSlack

Available Metrics

Pass Rate Drop

Alert when authentication pass rate falls below threshold

Failure Spike

Alert when failures exceed normal levels

New Sender Detected

Alert when a new IP starts sending as your domain

Policy Violation

Alert when emails are rejected or quarantined

DNS Change

Alert when SPF, DKIM, or DMARC records change

Volume Anomaly

Alert when email volume is unusually high or low

Comparison Operators

OperatorSymbolExample
Less than<Pass rate < 90%
Greater than>Failures > 100
Equals=Policy = reject
ChangesDNS record changes
ContainsSender contains 'unknown'

Notification Channels

Email

Send alerts to email addresses

All plans

Slack

Post to Slack channels

Plus+

Discord

Post to Discord channels

Plus+

Microsoft Teams

Post to Teams channels

Pro+

Telegram

Send Telegram messages

Pro+

Custom Webhook

POST to any URL

Plus+

Managing Alerts

Snooze

Temporarily disable alerts for maintenance windows

Enable/Disable

Toggle rules on or off without deleting

Delete

Remove rules you no longer need

Alert Grouping

Similar alerts are automatically grouped to reduce noise. You can group by domain, alert type, or severity level.

Plan Limits

PlanCustom RulesChannels
FreeEmail only
Plus3 rulesEmail, Slack, Discord, Webhook
Professional25 rulesAll channels
EnterpriseUnlimitedAll channels + custom

Next Steps