Documentation

Learn how to integrate and use DDMARC.

Docs/Using DDMARC/Dashboard
10 minutes

Dashboard Guide

A tour of the DDMARC dashboard — where each page lives, what the Overview widgets are telling you, and which features come with which plan.

Navigation

The sidebar is organised into four groups. Management is collapsed by default; Lookalike Domains and Team appear once your plan includes them. Partner (MSP) accounts get an additional block for customers, prospect scanning, billing, and branding.

Overview

  • DashboardKPI row, trends, and widgets across every domain
  • CompliancePer-domain scores, grades, and recommendations
  • Action CenterPrioritised list of what to fix next

Email Authentication

  • DomainsAdd domains, check DNS, and open a domain workspace
  • DNS MonitoringRecord checks, history, and change alerts
  • ReportsEvery aggregate (RUA) report received
  • SendersSending services and IPs, categorised
  • ARC ChainsAuthenticated Received Chain results for forwarded mail
  • TLS ReportsTLS-RPT delivery and negotiation failures
  • DNS PolicyCurrent policy posture per domain

Analysis & Actions

  • FailuresFailure Analysis: root causes, spoof clusters, fixes
  • RolloutsStaged policy rollouts from none to reject
  • NotificationsAlerts, alert rules, and delivery channels
  • Lookalike DomainsBrand-protection scanning for confusable domains

Management

  • ActivityAudit trail of who changed what
  • ExportsCSV exports of reports, senders, and activity
  • TeamInvite teammates and manage roles
  • SettingsOrganization, billing, and account settings

Command palette

Press Cmd +K (or Ctrl + K) to jump to any page by name. Some destinations — Forensic Reports in particular — are not in the sidebar and are reached from the palette, from the Failures page, or from a breadcrumb.

The Dashboard page

Your landing page after login. The header carries a date-range picker, and buttons for Upload Report, Add Domain, and Customize. A brand-new account sees a setup wizard here instead until the first report arrives.

The DDMARC dashboard: five KPI tiles across the top, an authentication trend chart, and the protocol breakdown donuts.
The Dashboard page. Every KPI tile is a link into the page that explains it.

KPI tiles

TileShows
Pass RateDMARC pass rate across all domains, with trend and sparkline
VolumeReports received in the selected period, with trend
FailuresMessages failing authentication — links to Failure Analysis
ComplianceAverage compliance score out of 100 across your domains
Pending IssuesOpen alerts awaiting attention

Widgets below the KPI row

  • Authentication Trend — pass and fail volume over time
  • Protocol Breakdown — DKIM and SPF pass-rate donuts
  • Compliance Overview — grade distribution and the domains needing attention
  • Failure Trend and Failure Breakdown
  • DMARC Policy Status — domains at none, quarantine, reject
  • Sender Overview — top sending services
  • Recent Alerts and Recent Reports
  • Time-of-Day Patterns heatmap
  • Top Email Sources
  • Period Comparison
  • Geographic Distribution

Any of these can be hidden from the Customize sheet — see Customizing the Dashboard.

Reports

Every aggregate (RUA) report DDMARC has received, newest first, with three KPI tiles above the table: Total Reports, Total Emails, and Pass Rate.

The DDMARC Reports page listing aggregate reports by reporter, date range, policy, email count, pass percentage, and failures.
Reports list. Domain is a filter above the table rather than a column.

Report list columns

ColumnDescription
ReporterOrganization that sent the report, with the domain it covers underneath
Date RangePeriod covered by the report (usually 24 hours)
PolicyThe policy that was published when the report was generated
EmailsNumber of messages in the report
Pass %Share of messages passing DMARC, colour-coded
FailMessages that failed DMARC

Report details

Click any row to see the per-source breakdown: source IP, country, ASN, SPF and DKIM results, alignment, and the disposition applied. See Reading Reports for how to interpret it.

Domains

The Domains page lists every monitored domain with its verification state, DMARC policy, pass rate, and DNS health card — including the advisory DNSSEC and DANE panels. Click a domain to open its workspace.

Domain list

Add and remove domains, run a DNS check, and see health at a glance. Your plan sets the domain limit.

DNS & Setup tab

Copy-paste ready TXT records for SPF, DKIM, DMARC, and optional MTA-STS and BIMI — including the RUA and RUF addresses unique to that domain.

Domain workspace tabs

  • Overview — traffic, pass rate, and health for this domain
  • DNS & Setup — the records to publish, plus verification
  • Policy — current policy and how to tighten it
  • Hosted Services — managed MTA-STS, BIMI, and DKIM hosting
  • Threats — spoofing and lookalike signals for this domain
  • Notifications — per-domain alert settings
A DDMARC domain workspace showing the Overview tab with health, policy, and traffic for a single domain.
A domain workspace. Tabs run across the top: Overview, DNS & Setup, Policy, Hosted Services, Threats, Notifications.

Senders

Every service and IP that has sent mail claiming your domain, with pass rates and remediation guidance. Full detail in the Senders guide.

Authenticating senders

Sources passing SPF or DKIM with alignment. These are your legitimate mail streams.

Failing senders

Sources failing authentication — either spoofing, or a real service missing SPF/DKIM setup. The Failures page tells you which.

Sender categories

Every sender carries one of seven categories. New senders start as Unknown until you classify them.

UnknownMarketingTransactionalInternalThird-partySuspiciousBlocked

Failures

The Failures page is where you diagnose authentication problems rather than just count them. It classifies root causes, groups likely spoofing campaigns, and links each cause back to the sender that caused it.

Root cause analysis

Failures grouped by cause, each with a suggested fix and links to the senders involved

Spoof campaign clusters

Related failures grouped by IP range, From: domain, and week

Most-spoofed domains

Which header-From domains attackers are impersonating

Time to resolution

How long DNS misconfigurations take you to fix, derived from monitoring checks

Read the full walkthrough in Failure Analysis.

DNS Monitoring

Six record types are checked and scored. Two more are collected as advisory information.

Monitored records

RecordPurposeAvailability
SPFAuthorize mail servers to send on your behalfMonitor+
DKIMCryptographically sign emails for authenticityMonitor+
DMARCDefine policy for handling authentication failuresMonitor+
TLS-RPTReceive TLS connection failure reportsProtect+
MTA-STSEnforce TLS encryption for inbound emailProtect+
BIMIDisplay brand logo in email clientsProtect+
DNSSECSigned DNS responses — reported, never scoredAdvisory
DANE / TLSACertificate pinning for SMTP, with live cert match — reported, never scoredAdvisory

Advisory means advisory

DNSSEC and DANE/TLSA results carry an Advisory badge on the domain health card. They are worth zero points and can never raise or lower your grade — see Security Score.

Check Now

Run an on-demand DNS check for a domain at any time, on any plan. Results update the health card and score immediately.

Scheduled monitoring

Protect+

Automatic checks with change alerts. The fastest cadence is set by your plan: Protect every 24 hours, Growth every 12, Professional and Partner every 6, Enterprise hourly. Monitor is manual-only.

The DDMARC DNS Monitoring page listing each domain's record status and last check time.
DNS Monitoring. Each domain opens to Current Status and History tabs.

TLS ReportsProtect+

TLS-RPT (RFC 8460) reports reveal TLS negotiation failures between sending mail servers and your domain, helping you find and fix encryption issues:

Report analysis

  • Policy-level success and failure counts
  • Failure type breakdown (certificate, STARTTLS, DANE)
  • Sending MTA and receiving MX identification
  • Per-policy detailed failure reasons
  • Reporting organization metadata
  • Trend analysis across reporting periods

Failure types

Categorises failures such as certificate-expired, certificate-host-mismatch, starttls-not-supported, and sts-policy-invalid, per RFC 8460.

Forensic ReportsProtect+

Forensic (RUF) reports describe individual failed messages. There is no sidebar entry — open them from the Forensic Reports (RUF) card on the Failures page, or with the command palette.

What's included

  • Source IP with country, ASN, and ASN organization
  • Original mail-from and rcpt-to addresses
  • The full Authentication-Results header, parsed
  • A redacted sample of the original message headers
  • Failure type and reported domain
  • Delivery result applied by the receiver

Privacy note

Forensic reports can contain personal data. DDMARC drops tracking-oriented headers, caps how many headers and how much of each it stores, and puts the results behind role-based access control. See Forensic Reports for exactly what is kept.

ExportsProtect+

Three CSV exports are available for offline analysis and compliance reporting:

DMARC Reports

Report records with authentication results, source IPs, and disposition.

Senders

Sender data with categories, pass rates, geolocation, and notes.

Activity Log

Audit trail with timestamps, actions, users, and IP addresses.

Filtering & search

Use the controls at the top of each page to narrow what you are looking at:

Date range

Last 7, 14, 30, or 90 days, plus this/last week, this/last month, this/last quarter, and year to date.

Filters

Scope to a single domain, or filter by result type, reporter, or sender category depending on the page.

Search

Search by domain name, IP address, ASN organization, or reporter name.

Features by plan

Self-serve tiers. Managed service providers also have Partner Starter ($99/mo) and Partner ($299/mo), both metered by customer domain count.

Monitor

Free

  • 2 domains
  • 30-day data retention
  • Basic analytics
  • Manual DNS checks only
  • Email reports

Protect

$29/mo

  • 5 domains
  • 90-day data retention
  • Advanced analytics & DNS trends
  • Scheduled DNS checks (every 24h)
  • TLS-RPT reports
  • Forensic (RUF) reports
  • CSV exports
  • Slack & Discord alerts
  • Alert rules + API access

Growth

$69/mo

  • 15 domains
  • 180-day data retention
  • Everything in Protect
  • Scheduled DNS checks (every 12h)
  • Managed MTA-STS & BIMI hosting
  • ARC chain monitoring
  • Telegram & Teams alerts
  • Team collaboration

Professional

$99/mo

  • 25 domains
  • 365-day data retention
  • Scheduled DNS checks (every 6h)
  • Custom DKIM selectors
  • Policy rollout automation
  • Lookalike domain detection
  • AI posture explainer
  • Compliance reports & bulk-sender matrix
  • Priority support

Enterprise

Contact us

  • Unlimited domains
  • 365-day data retention
  • Hourly scheduled DNS checks
  • SSO/SAML
  • Custom SLA
  • White-label options

Next Steps