DMARC Monitoring
Written By Eric Heller
Last updated 1 day ago
NAVIGATION Analysis > DMARC Monitoring
PERMISSIONS Admin role required
REQUIREMENTS DMARC Monitoring is available only with INKY Pro
Overview
Domain-based Message Authentication, Reporting & Conformance (DMARC) is an email authentication protocol that protects your domain from spoofing and phishing by ensuring only authorized senders can send mail on your behalf. When a sender fails DMARC validation, INKY treats them as unauthorized, even if they appear on an Allow List.
INKY's DMARC Monitoring solution collects the aggregate reports that receiving mail servers generate based on your DMARC record, then aggregates and analyzes that data in an intuitive dashboard. This empowers administrators to quickly identify issues, confirm legitimate sending sources, and maintain domain integrity.
In INKY, DMARC plays an integral role in several features:
Allow Lists: DMARC authentication is recommended for safer allow listing. It blocks spoofed emails from matching your allow list by requiring SPF or DKIM validation of the FROM header. You can manage Allow List DMARC settings in the Admin Center. See Allow List Overview.
Block Lists: DMARC authentication also applies to block list entries to improve security.
Known External Senders: Only senders who pass SPF/DKIM/DMARC authentication receive the "Known External" blue banner, signaling trusted, verified external contacts to users.
Third-party senders: If a service sending mail on your behalf is properly authenticated with SPF/DKIM/DMARC for your domain, INKY honors that automatically without extra configuration.
DMARC Monitoring Page
The DMARC Monitoring overview page provides a centralized view of domain authentication status and reporting. Each domain displays its current DMARC, SPF, and DKIM configuration.
The DMARC Aggregate Report Data dashboard displays report data aggregated from DMARC reports received by INKY based on any DMARC DNS records configured.

Sender Authentication Configuration Section
This section displays the authentication configuration for all domains in your organization, including DMARC, SPF, and DKIM records. If the section is collapsed, click the ^ icon to expand it.
Your domains may already appear in the list and be awaiting configuration.
Each domain displays its current DMARC, SPF, and DKIM status. Do not be concerned if some checks are not yet passing. After you configure a DMARC record, synchronization can take up to 24 hours. In addition, the DKIM status will not change to Passed until the first DMARC report is received.

DMARC Setup Instructions Panel
Displayed when the Cog icon is selected for a domain. Provides the DNS record information needed to enable DMARC reporting to INKY.

How to…
Set up DMARC monitoring for a domain with no existing DMARC record
Set up DMARC monitoring for a domain with no existing DMARC record
BEFORE YOU BEGIN Ensure you have access to your DNS hosting provider (e.g., GoDaddy, Cloudflare, Namecheap). DNS propagation may take up to 24 hours after making changes.
To configure DMARC monitoring for a domain that has no existing DMARC record, complete the following steps:
In INKY, select Analysis > DMARC Monitoring.
If the Sender Authentication Configuration (DMARC, SPF, & DKIM Records) section is collapsed, expand it by clicking the ^ icon.
Find the domain that needs DMARC configured and select the Cog icon on that row.
Review the DMARC Setup Instructions.

Log into your DNS hosting provider and add a TXT record using the values above.
Repeat steps 3 through 5 for all other domains in your list that you want INKY to monitor.
After completing these steps, INKY will begin receiving DMARC aggregate reports for your domain. Allow up to 24 hours for DNS propagation and initial report delivery.
Add INKY reporting to an existing DMARC record
Add INKY reporting to an existing DMARC record
If the domain you want monitored by INKY already has a DMARC record that you utilize and now you want INKY to aggregate reports for you, you can simply add INKY’s rua address to your record. This can be done in addition to what’s already configured or replace it.
To add INKY's reporting address to a domain that already has a DMARC record configured, complete the following steps:
In INKY, select Analysis > DMARC Monitoring.
Locate the domain in the Sender Authentication Configuration section.
In your DNS hosting provider, find the existing DMARC TXT record for _dmarc.{domain}.com.
Add INKY's RUA address to the record. You have two options:
Append INKY's address alongside your existing address, separated by a comma:
v=DMARC1; p=reject; rua=mailto:reports@reports-sg.inkydmarc.com, mailto:your-existing@example.com;Or replace the existing address with INKY's address:
v=DMARC1; p=none; rua=mailto:reports@reports-sg.inkydmarc.com;
Save the updated DNS record.
Once saved, INKY will receive aggregate DMARC reports in addition to (or instead of) your previously configured address. Allow up to 24 hours for propagation.
Confirm DMARC configuration
Confirm DMARC configuration
To verify that DMARC monitoring is correctly configured for your domains, complete the following steps:
In INKY, select Analysis > DMARC Monitoring.
Check the DMARC column for your configured domains.
A green check mark indicates the record is properly set up to send aggregate DMARC reports to INKY.
Click a green check mark to view your record details and a confirmation statement.

NOTE If checks are not yet green, allow up to 24 hours for DNS propagation and for INKY to receive the first aggregate report. DKIM will not turn green until after the first DMARC report is received.
FAQ
How does DMARC work with Allow Lists in INKY?
When DMARC authentication is enabled for an Allow List entry, INKY only matches that entry if the sender passes DMARC validation, meaning SPF or DKIM authenticates for the FROM header. This prevents attackers from spoofing allowed domains and gaining unauthorized access through the Allow List.
Should I always enable DMARC authentication for Allow List entries?
Yes, it is recommended to enable DMARC authentication for Allow List entries unless you specifically need to allow unauthenticated email. By default, DMARC authentication is selected when adding entries to the Allow List from the message view.
What happens if a sender does not pass DMARC?
If a sender does not pass DMARC, even if they are on your Allow List, their email will not be treated as allowed. DMARC authentication applies to both Allow List and Block List entries to improve overall security.
How long does it take for DMARC reports to appear in INKY?
It may take up to 24 hours after completing DNS configuration to receive DMARC aggregate results, depending on DNS propagation, sending habits, and aggregate report timing. DKIM status will not turn green until after the first DMARC report is received.
Can I keep my existing reporting address and also add INKY?
Yes. DMARC allows multiple addresses in the RUA section if they are separated by a comma. You can add INKY's reporting address alongside your existing address without removing it. Only replace your existing address if you no longer need reports sent there.