dmarcproof dmarcproof Sign in
Reject forged reports

Reject forged DMARC reports before you parse them.

A free, confidence-scored allowlist of the systems that legitimately send DMARC aggregate (RUA) reports — built from transport evidence, not the report contents.

Check an IP

The allowlist is still being built — most IPs return "not recognized yet." See why below.

Why add your domain
Protect your reporting

Reject forged or poisoned RUA reports at the connection layer, before anything parses them.

Why we need you
Help build the allowlist

We're in data-discovery mode. Every reporting domain sharpens the model and gets us to a published list faster.

Free & non-commercial

No cost, no catch. We never read or store your report contents — only the sender's connection metadata.

How it works
01
Add & verify your domain

Prove control with a DNS record; we issue two RUA addresses to point your DMARC rua= at.

02
We characterize the senders

As reports arrive we record the sending server's transport evidence (IP, TLS, DKIM, FCrDNS) — never the XML.

03
Confidence-scored allowlist

Cross-domain, transport-authenticated senders earn confidence — the basis of the published allowlist.

We never read your reports

The DMARC report XML is discarded unread — never parsed, never stored. We characterize only the sending server's connection.

Read the full transparency statement →