DMARCLY logo

DMARCLY

Flat-priced DMARC monitoring that scales to fifteen domains without a sales call

DMARCLY is an email authentication platform that ingests DMARC aggregate and forensic reports, presents them as sender analytics with vendor identification and geographic mapping, and adds Safe SPF for the ten DNS lookup limit plus BIMI and MTA-STS support, so organizations can reach a p=reject policy; it is an authentication monitoring product and does not warm mailboxes or test inbox placement.

Visit website

Overview

DMARCLY does one of the three jobs in this category: SPF, DKIM, and DMARC authentication monitoring. It does not build sender reputation and it does not measure inbox placement. What it does is take the DMARC aggregate reports that every receiving mail server already produces about your domain and turn them into a picture of who is sending as you, which of those senders authenticate correctly, and what is left to fix before you can safely enforce a policy.

The reason to look at DMARCLY specifically is the pricing ladder. Where most of this field either caps you at two domains on the entry tier or hides multi-domain pricing behind a sales conversation, DMARCLY publishes a flat, legible progression: $17.99 a month for two domains, $39.99 for eight, $69 for fifteen, and $199 for two hundred. That last figure is the one that matters. A company with a portfolio of parked and sending domains can get every one of them monitored for less than what dmarcian charges for eight, and it can do so by clicking upgrade rather than filling in a contact form.

The feature set is complete rather than exceptional. Aggregate and forensic reports, subdomain detection, email vendor identification, IP reputation monitoring, geographic maps, BIMI, MTA-STS and TLS-RPT, and two-factor authentication all appear on the entry tier. Safe SPF, which handles the ten DNS lookup limit that silently breaks SPF on domains with many vendors, arrives at Growth and is limited by count: one Safe SPF domain on Growth, two on Business, four on Enterprise, which is a subtle gate worth reading before you buy.

The honest limitation is depth of guidance. DMARCLY assumes you know roughly what SPF alignment means, or are willing to read documentation that is competent but not the reference text dmarcian publishes. It is a good tool in the hands of someone technical, and a slightly bare one for a small business owner with no email background who wants to be led step by step. A fourteen-day trial on every tier makes that easy to test before committing.

Best for

Companies and agencies with several domains that want published, predictable, self-serve pricing for DMARC monitoring, plus SPF lookup remediation, without a sales conversation or an enterprise contract.

Not the right fit for

  • Anyone whose real problem is cold email landing in spam; DMARC monitoring confirms authentication and says nothing about placement, and authenticated mail gets filtered on reputation grounds constantly.
  • Buyers who want inbox placement evidence; DMARC reports do not carry placement data, so no DMARC platform can tell you whether a message reached the inbox or the junk folder.
  • Small business owners with no email background who need to be walked through every step; DMARCLY instruments the problem competently but explains it less thoroughly than dmarcian or EasyDMARC.
  • Teams that need Safe SPF across many domains; the Safe SPF domain count is capped separately from the domain count, at one, two, and four across the paid tiers.
  • Anyone looking for warming or reputation building; there is none here and there never will be, because that is a different product category.

How it works

  1. 1

    You add your domains and publish a DMARC record with DMARCLY's reporting address in the rua tag, and optionally the ruf tag for forensic reports. Nothing changes about how your mail is sent; you are only asking receivers to report.

  2. 2

    Aggregate reports arrive within a day or two from Google, Microsoft, Yahoo, and other receivers. DMARCLY parses them into per-source views showing message volume, SPF and DKIM alignment results, named vendor identification where the sending infrastructure is recognized, and a geographic map of where mail claiming to be from you originates.

  3. 3

    You resolve the sending list one source at a time: authorize legitimate senders in SPF, enable DKIM signing at each vendor, and investigate anything unrecognized. Where SPF has grown past the ten DNS lookup limit, Safe SPF on Growth and above resolves the overflow without you flattening records by hand.

  4. 4

    As the compliance rate approaches full coverage of legitimate mail, you tighten policy in stages: p=none, then p=quarantine with a percentage rollout, then p=reject. IP reputation and, on Business and above, domain blacklist monitoring keep watch afterwards, and alerts flag new or failing sources.

Feature breakdown

22 features in 4 modules

DMARC report analytics

The core job: making the mail claiming to be from your domain visible and legible.
Aggregate report processing
Parses rua reports from every receiver that sends them, rendering per-source volume with SPF and DKIM alignment outcomes instead of daily XML attachments.
Forensic reports
Per-message failure detail included from the entry Professional tier, which is unusual; most competitors reserve forensics for mid or upper tiers. Coverage is still limited by receivers, most of which do not send failure reports.
Email vendor identification
Recognizes sending infrastructure and names the service, so a source reads as your marketing platform rather than an unlabelled IP range.
Subdomain detection
Surfaces subdomains sending mail under your organizational domain, which is how companies discover a forgotten mailing subdomain undermining an enforced policy.
Geographic mapping
Plots sending sources on a map, which is the fastest way to make spoofing legible to a non-technical stakeholder who needs to approve enforcement.
Data history by tier
Two months on Professional, four on Growth, six on Business, and a year on Enterprise. Anything with a monthly or quarterly rhythm needs at least four months to be diagnosable.

SPF, DKIM, and record tooling

Including Safe SPF, the answer to the lookup limit that quietly breaks SPF on established domains.
Safe SPF
Resolves SPF records that exceed the ten DNS lookup limit, a silent failure where SPF stops evaluating and every recipient sees a permerror. Available from the Growth tier, and capped at one, two, or four Safe SPF domains depending on plan.
SPF and DKIM diagnosis
Per-source separation of SPF authentication from SPF alignment and DKIM signing from DKIM alignment, which explains almost every confusing DMARC failure.
BIMI support
BIMI record handling for brands wanting a logo shown in supporting inboxes, included from the entry tier. Display at most large providers additionally requires a Verified Mark Certificate purchased separately from a certificate authority.
MTA-STS and TLS-RPT
Support for the transport encryption standards adjacent to DMARC, included from the entry tier rather than reserved for enterprise plans.
IP reputation monitoring
Tracks the reputation of the sending IPs appearing in your reports, included on every paid tier.
Domain blacklist monitoring
Adaptive domain blacklist checking from the Business tier, which is the closest DMARCLY comes to reputation work and is still monitoring rather than remediation.

Reaching enforcement

The path to p=reject, which is what the subscription buys.
Staged policy progression
Guidance for moving from p=none through p=quarantine with a percentage rollout to p=reject, with compliance rates as the readiness evidence.
Compliance rate tracking
A headline percentage for the share of your mail passing DMARC, the single number to watch before tightening policy.
Alerting
Notifications when new sending sources appear or authorized ones start failing, so regressions surface in days rather than at the next audit.
Domain groups
Groups domains for reporting and management, scaling from one group on Professional to unlimited on Enterprise, which is how an agency keeps client estates separate.

Plans, seats, and access

The published ladder that makes DMARCLY the multi-domain value option.
Published domain allowances
Two domains at $17.99, eight at $39.99, fifteen at $69, and two hundred at $199, all self-serve. No competitor in this group publishes a two-hundred-domain price at all.
Message volume ceilings
100,000 DMARC-compliant messages a month on Professional, 250,000 on Growth, one million on Business, and five million on Enterprise, counting reported messages rather than messages you sent.
User seats
One on Professional, three on Growth, five on Business, and unlimited on Enterprise, a more generous progression than dmarcian's.
API access
Available on the Enterprise tier at $199 a month, which is far cheaper API access than dmarcian's $600 Enterprise plan.
SSO and SAML
Enterprise tier, alongside user access control.
Fourteen-day free trial
Offered on every paid tier with self-serve registration, so evaluation requires no sales contact.

Use cases

4 documented

Company with a portfolio of brand and defensive domains

Forty domains are registered, six actually send mail, and the rest are parked and vulnerable to being spoofed by anyone who notices they have no DMARC policy.

The Enterprise tier covers two hundred domains at $199 a month, parked domains get a p=reject record with no legitimate mail to break, and the sending domains are worked through one at a time.

Agency managing client authentication

Twelve client domains need monitoring and separate reporting, and buying twelve individual subscriptions is absurd.

Business at $69 covers fifteen domains with five domain groups and five users, giving each client its own reporting scope inside one subscription.

Ops engineer facing an SPF permerror

The SPF record has accumulated eleven includes over five years and has crossed the ten DNS lookup limit, so SPF now fails silently for every recipient.

Safe SPF on the Growth tier resolves the overflow, aggregate reports confirm pass rates recovering across sources, and the record stops needing manual flattening every time a vendor changes.

Business responding to the Google and Yahoo bulk sender rules

The marketing platform is warning that the sending domain has no DMARC record, and volume is above the bulk sender threshold.

A Professional subscription publishes p=none, reports identify the four real sending vendors within a fortnight, and the domain reaches enforcement inside two months.

Pricing

from $17.99 per month (Professional)

Flat-rate subscription tiered by number of domains, monthly DMARC-compliant message volume, data history, user seats, and Safe SPF domain count.

PlanPriceIncludes
Professional$17.99
per month
  • Up to 2 domains
  • 100,000 DMARC-compliant messages per month
  • 2 months of data history
  • 1 user, 1 domain group
  • Aggregate and forensic reports, BIMI, MTA-STS and TLS-RPT, IP reputation monitoring

Forensic reports on the entry tier is genuinely unusual; most competitors gate them higher.

Growth$39.99
per month
  • Up to 8 domains
  • 250,000 messages per month
  • 4 months of data history
  • 3 users, 3 domain groups
  • Safe SPF on 1 domain, live chat support

The Safe SPF domain cap of one is easy to miss and matters if the lookup overflow affects several domains.

Business$69
per month
  • Up to 15 domains
  • 1,000,000 messages per month
  • 6 months of data history
  • 5 users, 5 domain groups
  • Safe SPF on 2 domains, domain and adaptive blacklist monitoring

Fifteen domains at $69 is the price to beat in this group; dmarcian charges $600 for the same count.

Enterprise$199
per month
  • Up to 200 domains
  • 5,000,000 messages per month
  • 1 year of data history
  • Unlimited users and domain groups
  • Safe SPF on 4 domains, API, user access control, SSO and SAML

A published two-hundred-domain self-serve price is unique in this field.

Billing notes

  • All four tiers are self-serve with a fourteen-day trial and no sales contact required, including the two-hundred-domain Enterprise plan.
  • Safe SPF domain count is gated separately from total domain count, at one, two, and four across Growth, Business, and Enterprise; buyers with lookup overflow on several domains should check this before choosing a tier.
  • Message volume counts DMARC-compliant messages reported by receivers, which includes vendor mail sent on your behalf and mail spoofed by third parties, not only mail you deliberately sent.
  • Data history is short on the lower tiers at two and four months, which limits diagnosis of anything with a quarterly rhythm.
  • API access lands on the $199 Enterprise tier, which is far cheaper programmatic access than most competitors offer.
  • There is no free plan, so the fourteen-day trial is the only zero-cost evaluation path.

Value assessment: DMARCLY has the best price-per-domain curve in self-serve DMARC monitoring, and the curve stays legible all the way up. Fifteen domains for $69 against dmarcian's $600 for the same count is not a close comparison, and two hundred domains at $199 with API access included is a figure no competitor publishes at all. What you give up is guidance: the interface and documentation assume competence rather than building it, and the Safe SPF domain caps are a real gate at the lower tiers. For a technically capable buyer with three or more domains, this is the correct default. For a single-domain business with a non-technical owner, EasyDMARC or dmarcian will produce a better outcome despite costing more per domain.

Strengths & limitations

Strengths

  • The clearest and cheapest published multi-domain ladder in the category, with two hundred domains available self-serve at $199 a month.
  • Forensic reports included on the entry tier, where most competitors reserve them for mid or upper plans.
  • Safe SPF handles the ten DNS lookup overflow, the silent failure mode most established domains suffer from without knowing.
  • BIMI, MTA-STS, and TLS-RPT support on every paid tier rather than reserved for enterprise contracts.
  • API access at $199 a month, roughly a third of what dmarcian charges for programmatic access.
  • Fourteen-day trial on every tier with self-serve registration and no sales conversation at any point.
  • Domain groups make client separation practical for agencies without buying separate subscriptions.

Limitations

  • Documentation and in-product guidance are competent but thin next to dmarcian or EasyDMARC; a non-technical owner will find themselves reading elsewhere.
  • Safe SPF domain counts are capped separately at one, two, and four, so multi-domain buyers with widespread SPF overflow may need a higher tier than the domain count alone suggests.
  • Short data history on the lower tiers, two months on Professional and four on Growth, which is not enough to diagnose quarterly sending patterns.
  • No free plan at all, so evaluation is limited to the fourteen-day trial.
  • No hosted DMARC or DKIM record management; DMARCLY diagnoses and instruments but you maintain your own DNS, unlike PowerDMARC.
  • No inbox placement testing, so it cannot tell you whether mail landed in the inbox, promotions, or spam.
  • No warming capability, so a new sending domain or mailbox still needs a separate tool.
  • Company ownership and headcount are not publicly disclosed, which is worth noting for a tool you are delegating authentication visibility to.

Head-to-head comparisons

6 alternatives

DMARCLY vs EasyDMARC

from $0 (Free, one domain), then $35.99 per month billed annually (Plus)

EasyDMARC is the better-explained product with stronger vendor naming and a useful free tier, but it caps at four domains on a $71.99 plan where DMARCLY covers fifteen at $69. Take EasyDMARC if a non-technical owner is running this alone and you have one or two domains; take DMARCLY the moment your domain count passes three and you have someone technical to drive it.

Full DMARCLY vs EasyDMARC comparison

DMARCLY vs PowerDMARC

from $0 (Free), then Basic from around $8 per month by volume, about $12 per month billed annually at the 100,000-email step

PowerDMARC is cheaper at the very bottom, roughly $12 to $15 for five domains, and hosts your SPF, DKIM, DMARC, BIMI, and MTA-STS records, which DMARCLY does not. DMARCLY counters with a fully published ladder up to two hundred domains and API access at $199 where PowerDMARC quotes everything above Basic. Pick PowerDMARC for hosted records and the lowest entry price; pick DMARCLY for predictable scaling and no sales gate.

Full DMARCLY vs PowerDMARC comparison

DMARCLY vs dmarcian

from $0 (Personal, non-business use), then $24 per month (Basic)

dmarcian was founded by the author of the DMARC specification and has by far the better documentation and diagnostic inspectors, but charges $240 for eight domains and $600 for fifteen against DMARCLY's $39.99 and $69. Choose dmarcian when you want to be taught the standard on one or two domains; choose DMARCLY when you have a domain estate and a budget.

Full DMARCLY vs dmarcian comparison

DMARCLY vs URIports

from $1.25 per month (Sand, personal), $6 per month billed annually (Pebble)

URIports undercuts even DMARCLY, at $30 a month for twenty-five domains and $120 for a hundred, and adds browser-side CSP and certificate monitoring. DMARCLY offers more email-specific tooling, including Safe SPF and blacklist monitoring, and a clearer route to enforcement. Take URIports if you are a technical operator watching many domains cheaply; take DMARCLY if the project is specifically getting email authentication to p=reject.

Full DMARCLY vs URIports comparison

DMARCLY vs Red Sift OnDMARC

from $9 per month billed annually (Express)

OnDMARC Express is cheaper than anything DMARCLY offers, $9 a month for four domains with hosted record services, but it stops dead there: the next Red Sift tier is quoted by sales and built for twenty-five sender domains. DMARCLY publishes the whole ladder to two hundred. Start on OnDMARC Express if you are small and staying small; choose DMARCLY if you expect to grow past four domains.

Full DMARCLY vs Red Sift OnDMARC comparison

DMARCLY vs GlockApps

from $59/mo (Essential, billed annually)

GlockApps bundles DMARC analytics into a platform centred on seed-list placement testing and blacklist monitoring. DMARCLY does authentication only, and does it with more domains, Safe SPF, and a clearer enforcement path. If your question is where mail lands, GlockApps; if your question is who sends as your domains and how to stop them, DMARCLY.

Full DMARCLY vs GlockApps comparison

Implementation & onboarding

Setup time
Thirty minutes to add domains and publish records. Reaching a defensible p=reject takes four to eight weeks of calendar time for a typical small business, governed by how long it takes every legitimate sender to appear in a report and be fixed.
Learning curve
Moderate to high depending on your background. The dashboards are clear if you already understand alignment; if you do not, DMARCLY will not teach you as thoroughly as dmarcian's documentation would.
Onboarding
Entirely self-serve with a fourteen-day trial on every tier, including the two-hundred-domain plan. Support moves from email on Professional to live chat from Growth upward.
Migration notes
Switching from another DMARC vendor means repointing the rua tag in your DMARC record; report history does not transfer between platforms, so list both addresses in parallel for a few weeks if continuity matters. If you adopt Safe SPF, note that leaving later means rebuilding your own SPF record from the authorized sender list.

Platform, API & security

Platforms
Web application
API
API access is available on the Enterprise tier at $199 a month, alongside user access control and SSO.
Compliance
GDPR
Data residency
Not published as a customer-selectable option.
SSO
SSO and SAML on the Enterprise tier; two-factor authentication is available on all paid tiers.
Security notes
DMARC aggregate reports contain sending IPs and authentication results rather than message bodies. Forensic reports, included from the entry tier here, can carry headers and sometimes partial content from the receivers that send them, so enable ruf deliberately on sensitive domains. Two-factor authentication is available on every paid plan.

Support & resources

Channels
Email support on ProfessionalLive chat from Growth upward
Documentation
Practical documentation covering SPF, DKIM, DMARC, BIMI, and MTA-STS setup, competent but less exhaustive than the reference material dmarcian publishes.
Community
No large official user community; the product is documentation-led rather than forum-led.

Company

Founded
2018
Headquarters
Not publicly disclosed
Ownership
Privately held, independent
Employees
Not disclosed
Funding
No disclosed outside funding.

Timeline

  1. 2018DMARCLY launches as an independent DMARC reporting platform aimed at organizations priced out of enterprise authentication tooling.
  2. 2020Adds Safe SPF to address the ten DNS lookup limit, the failure mode that silently breaks SPF on domains with many vendors.
  3. 2022Extends coverage to BIMI, MTA-STS, and TLS-RPT across all paid tiers rather than gating them to enterprise plans.
  4. 2024The Google and Yahoo bulk sender requirements drive a wave of small business DMARC adoption, favouring vendors with published self-serve pricing.
  5. 2026Continues to publish the widest self-serve domain ladder in the category, up to two hundred domains with API access at $199 a month.

Integrations

  • DNS providers via published record changes
  • Google Workspace as a sending source
  • Microsoft 365 as a sending source
  • Marketing and transactional email vendors, identified by name in reports
  • Blacklist and IP reputation data sources
  • API access on the Enterprise tier
  • SSO and SAML on the Enterprise tier

Frequently asked questions

10 questions

What is DMARCLY?

DMARCLY is an email authentication monitoring platform. It collects the DMARC aggregate and forensic reports that receiving mail servers generate about your domains, presents them as per-source analytics with vendor identification and geographic mapping, and supports the path to an enforced p=reject policy. It also provides Safe SPF for the DNS lookup limit, plus BIMI, MTA-STS, and TLS-RPT support.

Which of the three deliverability jobs does DMARCLY do?

Authentication monitoring, and nothing else. It does not warm mailboxes and it does not test inbox placement. If your outbound is landing in spam while passing SPF, DKIM, and DMARC, DMARCLY will confirm authentication is healthy and stop there; that problem belongs to a warming tool or a placement tester.

How much does DMARCLY cost?

Professional is $17.99 a month for two domains, Growth is $39.99 for eight, Business is $69 for fifteen, and Enterprise is $199 for two hundred. All four are self-serve with a fourteen-day trial. There is no free plan.

How many domains does each tier cover and what does adding one cost?

Two, eight, fifteen, and two hundred across the four tiers. DMARCLY does not publish a per-domain add-on price; the model is to move up a tier, and because the ladder is published and self-serve that is a click rather than a sales call. Fifteen domains at $69 and two hundred at $199 are the cheapest published figures at those counts in this field.

What are the DMARC report volume limits?

100,000 DMARC-compliant messages a month on Professional, 250,000 on Growth, one million on Business, and five million on Enterprise. That counts messages receivers reported on, which includes mail your SaaS vendors send on your behalf and mail spoofed by third parties, so a domain under impersonation consumes allowance faster than your own sending would suggest.

Does DMARCLY support hosted SPF, DKIM, and BIMI records?

Partly. Safe SPF handles SPF records that have exceeded the ten DNS lookup limit, available from Growth and capped at one, two, or four Safe SPF domains depending on tier. BIMI and MTA-STS are supported from the entry tier. DMARCLY does not host DKIM or DMARC records the way PowerDMARC does, so you publish and maintain those in your own DNS. BIMI logo display at most large providers also requires a Verified Mark Certificate bought separately.

How are aggregate and forensic reports presented to a non-expert?

Aggregate reports become per-source rows with volume, separate SPF and DKIM alignment outcomes, named vendor identification, and a map of sending locations. Forensic reports, included from the entry tier, show individual failing messages, though most large mailbox providers do not send them so coverage is partial. The geographic view is usually the thing that makes spoofing legible to a non-technical stakeholder.

How does DMARCLY get me to a p=reject policy?

You publish p=none first so receivers report without acting on failures. As reports arrive, you authorize each legitimate sender in SPF and enable DKIM signing at each vendor, using Safe SPF if your record has overflowed the lookup limit. When your compliance rate covers your legitimate mail consistently, you move to p=quarantine with a percentage rollout, then to p=reject. Four to eight weeks is realistic, limited by observing a full sending cycle rather than by the tool.

Do I still need a warming tool or a placement tester?

If you send cold outbound or you are starting a new domain, yes. Authentication is a prerequisite for placement, not a substitute. A common stack is DMARCLY for authentication across your domains, a warming service such as MailReach or TrulyInbox for new mailboxes, and a placement tester such as GlockApps or Unspam for evidence of where mail lands.

Who owns DMARCLY?

DMARCLY is an independent, privately held vendor with no disclosed outside funding. Unlike dmarcian or EasyDMARC, it does not publish detailed company information, which is worth weighing if vendor transparency matters to your procurement process.

Editorial verdict

DMARCLY is the multi-domain value pick in DMARC monitoring, and the reason is simply arithmetic: fifteen domains for $69 a month against dmarcian's $600 for the same count, and a published two-hundred-domain self-serve tier at $199 with API access that nobody else in this field advertises. Forensic reports on the entry plan, Safe SPF for the DNS lookup overflow, and BIMI and MTA-STS support across all tiers make the feature set complete rather than merely cheap. What you are not buying is education. The documentation is adequate rather than definitive, the Safe SPF domain caps are an easy trap, and the company discloses very little about itself. Buy it if you have three or more domains and someone technical to drive the deployment. If one non-technical person is doing this alone on a single domain, pay more elsewhere for the hand-holding, and in either case do not expect it to say anything about whether your mail reaches the inbox.

Written by the SaaSTracker editorial team. Awards, when shown, are judged against the published criteria in our methodology.