DMARC monitoring

Got a DMARC report email? Let Faber watch the next one.

Connect the mailbox receiving future reports. Faber learns who sends mail as your domain and alerts you only when something needs attention.

Example report

Future reports, in the words you actually need.

DMARC reports are built for mail systems, not for the person who owns the domain. Once monitoring is set up, Faber turns future reports into short explanations and leaves the ordinary ones alone.

Example reportyourdomain.com
  1. Healthy: 98.7% of messages authenticated.
  2. New sender detected: an unfamiliar email service.
  3. Action: check whether this service is yours.

What these emails are

A receipt from the internet’s mailboxes.

They arrive automatically

Mail providers send aggregate reports to the address in your DMARC record, usually every day. They are not a warning by themselves.

They name the mail they saw

Each report says which systems sent mail claiming to be from your domain and whether the authentication checks passed.

They are hard to read

The useful facts are packed into XML, often inside a ZIP or GZIP attachment. That is why they tend to sit unopened.

How Faber helps

It learns what normal mail looks like first.

Reads the report

XML, ZIP, and GZIP reports are read safely, without asking you to decode them.

Learns normal senders

It builds a baseline of the services that legitimately send mail as each of your domains.

Flags what changed

Authentication failures, mail quarantined or rejected, and unfamiliar senders get your attention.

Stays quiet otherwise

When authentication is healthy and the sender is familiar, there is no new alert to chase.

Built for careful monitoring

It watches the reports without touching your mail setup.

Previewed first

You see the task’s preview before it runs live on future reports.

No email replies

It never replies from the monitored mailbox.

No DNS changes

It reads the reports you already receive; it does not change your DNS records.

No attachment archive

Report attachments are processed for the task and are not retained in task data.

Good fit when

The reports are already arriving, but nobody is reading them.

You receive XML-looking attachments with subjects such as “Report Domain.”

Your domain sends through more than one service, such as Google Workspace, Microsoft 365, a CRM, or a newsletter tool.

You want to know when an unfamiliar service starts sending as your domain.

You need failures called out without creating another daily security dashboard to check.

Let the next DMARC report explain itself.

Connect the mailbox receiving your reports, review Faber’s preview, and choose where an alert should go when a report needs attention.