How DMARCRadar works
Run the public checker - paste any domain to get an instant DMARC, SPF, and DKIM read, with no account needed.
Automatic DKIM selector scanning - DMARCRadar probes 38 common DKIM selectors in parallel to find your DKIM record.
Review prescriptive findings - each result comes with a severity, a plain-English explanation, and a suggested fix.
Sign up and add your domain - create a free DMARCRadar account and get a DNS record to publish, generated for your domain.
Verify DNS and start receiving reports - confirm the record is live; aggregate reports typically start arriving within 24 hours.
Monitor your dashboard - track senders, pass rates, and a 0–100 health score covering DMARC, SPF, DKIM, MTA-STS, TLS-RPT, and BIMI, with an A–F grade for every domain you monitor.
Configuration details
1. Run the public checker
Go to DMARCRadar and enter the domain you want to check - an apex domain or a subdomain. Press "Check." This first check is free, requires no account, and is rate-limited per IP address.
2. Automatic DKIM selector scanning
DKIM has no single record to look up - only per-selector records that vary by provider. DMARCRadar checks 38 common selectors automatically (covering providers like Google, Microsoft, Elastic Email, Mailchimp, Postmark, and OVH). If your provider uses an uncommon selector, the result will say so - you can paste a recent DKIM-Signature: header from a sent email and DMARCRadar reads the selector from it and re-checks.
3. Review prescriptive findings
The DMARC, SPF, and DKIM results are each shown as a card listing specific findings - not just pass/fail. Every finding has a severity (critical, warning, or informational), a plain-English explanation of why it matters, and guidance on how to fix it.
4. Sign up and add your domain
Click "Start tracking this domain" under your check results (or "Get started") to sign up. This creates a separate DMARCRadar account - it isn't the same login as your Elastic Email account. Enter your domain; DMARCRadar normalizes it and confirms what it detected.
You'll land on a Setup screen showing the DNS record to publish: host, record type, and value, each with a copy button. This record includes a reporting address that's unique to your account. If the domain already has a DMARC record, add this reporting address as a tag to the existing record instead of replacing it - DMARCRadar shows you exactly what to add.
5. Verify DNS and start receiving reports
Publish the record with your DNS provider, then click "Verify DNS." DMARCRadar performs a live lookup. If the record is found, the domain is marked verified. If not, you'll see a plain-English reason (record not found, incorrect value, or an existing DMARC record that needs the reporting tag added) and can re-verify once it's fixed.
Once verified, the first reports typically arrive within 24 hours, since most mailbox providers report on a daily cycle. Until then, the dashboard shows an "awaiting first report" state.
6. Monitor your dashboard
The account Overview shows a scorecard with DMARC, SPF, and DKIM pass rates and message counts a trend chart over a 7/30/60/90-day window you choose, and a tile per monitored domain. A banner flags any domain that still needs DNS verification or is awaiting its first report.
Clicking into a domain opens its dashboard: the same scorecard and trend chart scoped to that domain, an authentication breakdown, which mailbox providers are reporting on it, and a ranked list of sending sources. Clicking a sender opens a detail view with its IP information, pass rate, and - if it's an authorized sender that's failing - what specifically is misaligned.
The Health view shows every domain's health score and letter grade side by side, with issues across domains grouped into one prioritized list.
Key features
Public checker: get an instant DMARC, SPF, and DKIM read for any domain, free and with no signup required.
Automatic DKIM selector scanning: DMARCRadar checks 38 common DKIM selectors automatically, with a manual fallback for uncommon ones.
Prescriptive findings: results flag severity and explain why each finding matters, not just pass or fail.
Continuous monitoring: once verified, DMARCRadar parses your domain's daily DMARC reports into a dashboard, trend charts, and drill-down detail.
Health score and grade: every tracked domain gets a 0–100 health score - covering DMARC, SPF, DKIM, MTA-STS, TLS-RPT, BIMI and a matching A–F letter grade.
Sender visibility: see every sender using your domain, its identification (email service, IP, network), and whether it's authenticating.
Important notes
The public checker is free and doesn't require an account; it's rate-limited per IP address. Continuous monitoring requires a free signup - a separate DMARCRadar account, not your Elastic Email login.
If a domain already has a DMARC record, add DMARCRadar's reporting address as a tag to the existing record rather than replacing it.
First reports usually take up to 24 hours to arrive after verification, since most mailbox providers report daily.
Deleting a DMARCRadar account is permanent - all domains, reports, and settings are removed immediately and can't be restored.





