URIports logo

URIports

Cheap, broad report monitoring for domains, mail servers, and browsers

URIports is a domain monitoring platform that collects the reports your infrastructure already generates, DMARC aggregate and failure reports from mail receivers, SMTP TLS reports from sending servers, and Content Security Policy and Reporting API messages from visitors' browsers, and presents them as a single monitoring surface with DNS, certificate, and BIMI checks; on the email side it is an authentication monitoring tool and does not warm mailboxes or test inbox placement.

Visit website

Overview

URIports covers the third job in this category, SPF, DKIM, and DMARC authentication monitoring, but arrives at it from a different direction than the DMARC specialists. The premise is that modern infrastructure already emits a great deal of telemetry that almost nobody collects: mail receivers send DMARC aggregate reports, sending servers send SMTP TLS reports, and browsers send CSP violation and Reporting API messages. URIports gives you an endpoint for all of it and turns the resulting stream into monitoring.

For an email buyer, that breadth is either the reason to choose it or an irrelevance, depending on whether you also own the websites. The DMARC side is complete: aggregate and failure report ingestion, SPF, DKIM, and BIMI record checks, DNS monitoring, hosted MTA-STS policies, and TLS reporting for DANE and MTA-STS. What it does not do is hold your hand. There is little in the way of guided remediation or vendor-by-vendor setup wizards; you get accurate data, clear alerts, and the expectation that you know what to do with them.

The pricing is the headline. Pebble at $6 a month billed annually covers five domains and 100,000 reports a month. Stone at $30 covers twenty-five domains, adds DNS monitoring, certificate monitoring, and team access. Mountain at $120 covers a hundred domains with 2.5 million reports and ninety-day retention, and Himalaya at $480 covers four hundred. There is a Sand plan at $1.25 a month for three domains and personal use, extra domains sell in packs of ten for $12 a month, and every plan gets a one-month free trial with no card. Compare that against dmarcian charging $600 a month for fifteen domains and the value gap is not subtle.

The honest framing is that URIports is a technical operator's tool sold at a hobbyist's price. If you are an engineer, sysadmin, or agency running infrastructure for several domains, it is arguably the best value in this entire category. If you are a small business owner who has just learned what DMARC is and needs to be led to p=reject, the guidance you get from EasyDMARC or dmarcian is worth paying several times more for.

Best for

Technical operators, sysadmins, and agencies monitoring authentication across many domains on a small budget, particularly those who also own the websites and want CSP, DNS, and certificate monitoring in the same console.

Not the right fit for

  • Small business owners who need to be taught what DKIM alignment is; URIports reports accurately and explains sparingly, so a first-time deployer will struggle where EasyDMARC would carry them.
  • Anyone whose actual problem is cold email landing in spam; authentication monitoring proves your mail is signed correctly and says nothing about whether it reaches the inbox.
  • Buyers wanting inbox placement evidence; DMARC reports do not carry placement data, so no amount of report monitoring will answer that question.
  • Teams that want hosted SPF, DKIM, or DMARC records managed for them; URIports hosts MTA-STS policies but is otherwise a monitoring surface rather than a record manager.
  • Anyone looking for warming or sender reputation building, which URIports does not attempt in any form.

How it works

  1. 1

    You add a domain and URIports gives you reporting addresses to publish. For email, that means putting its address in the rua and optionally ruf tags of your DMARC record, and its TLS-RPT address in the corresponding record if you want transport reporting.

  2. 2

    Receiving mail servers begin sending aggregate reports within a day or two. URIports parses them into per-source views with SPF and DKIM alignment outcomes, so you can see which of your sending vendors authenticate correctly and which do not, and where unauthorized mail claiming to be from you is coming from.

  3. 3

    Alongside that, the platform checks the records themselves on a schedule: SPF, DKIM, BIMI, DNS entries, and SSL and TLS certificates, alerting when something changes or expires. Hosted MTA-STS policies can be served by URIports so you do not need to run the policy web endpoint yourself.

  4. 4

    On the web side, if you point your Content Security Policy report-uri and the Reporting API at URIports, browser-generated violation, crash, deprecation, and intervention reports land in the same console. For an email-only buyer this is simply unused capacity; for a team that owns both the domain and the site, it collapses two monitoring tools into one bill.

Feature breakdown

21 features in 4 modules

Email authentication monitoring

The DMARC job, done accurately and cheaply across a lot of domains.
DMARC aggregate report processing
Ingests rua reports from every receiver that sends them and renders per-source volume with SPF and DKIM alignment outcomes, replacing daily XML nobody opens.
DMARC failure reports
Per-message failure detail where receivers provide it, which is how a single misconfigured sender gets isolated. Coverage is limited by the fact that most large mailbox providers do not send failure reports at all.
SPF record monitoring
Checks the published SPF record for validity and for the ten DNS lookup limit that silently breaks SPF on domains with many vendors, alerting when it changes.
DKIM record monitoring
Watches published DKIM selectors and keys so a vendor rotating or removing a key does not quietly break signing for weeks.
BIMI monitoring
Checks BIMI record presence and validity for brands wanting a logo in supporting inboxes. Display at most large providers additionally requires a Verified Mark Certificate purchased separately.
Alignment separation
Distinguishes SPF authentication from SPF alignment and DKIM signing from DKIM alignment, which is where most confusing DMARC failures resolve.

Transport security monitoring

The SMTP TLS side that almost no small business tool bothers with.
SMTP TLS reporting
Collects TLS-RPT reports from sending servers showing whether mail to your domain was delivered over encrypted connections and where negotiation failed.
Hosted MTA-STS policies
URIports serves the MTA-STS policy endpoint on your behalf, removing the need to run a dedicated policy host, which is the main reason small organizations skip MTA-STS entirely.
DANE monitoring
Covers DANE alongside MTA-STS for organizations using DNSSEC-based transport security.
Certificate monitoring
Watches SSL and TLS certificate validity and expiry from the Stone tier, catching the classic weekend outage caused by an unrenewed certificate.

Domain and web monitoring

The breadth that makes URIports cheap per unit of coverage if you own the websites too.
DNS monitoring
Alerts on unexpected changes to DNS records from the Stone tier, which is both an operations safeguard and a security control.
Content Security Policy reporting
Collects CSP violation reports from visitors' browsers, letting you deploy a policy in report-only mode and tighten it on evidence rather than guesswork.
Reporting API coverage
Handles browser crash, deprecation, and intervention reports through the modern Reporting API, not just legacy CSP endpoints.
Network Error Logging
Captures client-side network failures that never reach your server logs, which is the only way to see certain classes of connectivity problem.
Security header checks
Monitors COOP, COEP, SRI, Permissions Policy, and security.txt presence alongside the email records.

Plans, scale, and access

The cheapest per-domain pricing in the category, with a legible ladder.
Published domain allowances
Three domains on Sand at $1.25, five on Pebble at $6, twenty-five on Stone at $30, a hundred on Mountain at $120, and four hundred on Himalaya at $480, all billed annually.
Add-on domain packs
Extra domains sell in packs of ten for $12 a month, which is a published per-domain price that most competitors in this field refuse to give.
Report volume ceilings
10,000 reports a month on Sand, 100,000 on Pebble, 500,000 on Stone, 2.5 million on Mountain, and 10 million on Himalaya, counting all report types together rather than DMARC alone.
Data retention
Thirty days on the lower tiers and ninety days on Mountain and Himalaya, which is short compared with the year that PowerDMARC and DMARCLY Enterprise offer.
Team access
Multi-user access from the Stone tier, with OIDC single sign-on arriving on Mountain.
One-month free trial
A full month with no credit card required, which is long enough to see a complete monthly sending cycle before deciding.

Use cases

4 documented

Agency monitoring authentication for twenty client domains

Each client needs DMARC visibility, but per-domain pricing at the specialist vendors makes the service line uneconomic.

The Stone plan at $30 a month covers twenty-five domains with team access, turning DMARC monitoring into a line item that costs less than an hour of billable time per year.

Sysadmin who owns both the mail and the websites

DMARC reporting, TLS reporting, DNS change alerting, certificate expiry, and CSP violation collection are currently four separate tools or, more realistically, four things nobody is watching.

All five land in one console on a single subscription, and the alerting catches an expiring certificate and a stray DNS change in the same month.

Organization enabling MTA-STS

MTA-STS requires serving a policy file from a dedicated web endpoint, which is enough friction that most small organizations abandon it.

URIports hosts the policy endpoint, TLS-RPT reporting confirms encrypted delivery, and the standard gets deployed in an afternoon rather than never.

Domain portfolio owner tightening parked domains

Forty registered domains have no DMARC record and can be spoofed freely by anyone who notices.

Mountain at $120 a month covers a hundred domains, parked domains get p=reject immediately since no legitimate mail can break, and the handful of real sending domains are worked through with report evidence.

Pricing

from $1.25 per month (Sand, personal), $6 per month billed annually (Pebble)

Flat-rate subscription tiered by number of domains, monthly report volume, and retention length, with add-on domain packs and a personal-use plan.

PlanPriceIncludes
Sand$1.25
per month
  • 3 domains
  • 10,000 reports per month
  • Personal and hobby use
  • Core DMARC and record monitoring

Effectively a nominal fee rather than a business plan, but a real working account.

Pebble$6
per month billed annually ($7 monthly)
  • 5 domains
  • 100,000 reports per month
  • 30 days of retention
  • DMARC aggregate and failure reports
  • SPF, DKIM, and BIMI record monitoring

Five domains for $6 a month is the cheapest serious DMARC monitoring published anywhere in this category.

Stone$30
per month billed annually ($33 monthly)
  • 25 domains
  • 500,000 reports per month
  • 30 days of retention
  • DNS monitoring and certificate monitoring
  • Team access

The agency tier, and where team access and infrastructure monitoring arrive.

Mountain$120
per month billed annually ($133 monthly)
  • 100 domains
  • 2,500,000 reports per month
  • 90 days of retention
  • OIDC single sign-on
  • Full web and email report coverage
Himalaya$480
per month billed annually ($530 monthly)
  • 400 domains
  • 10,000,000 reports per month
  • 90 days of retention
  • Security specialist support
  • Enterprise-scale reporting

Add-ons

  • Extra domain pack ($12 per month): Sold in packs of ten domains, a published per-domain price most competitors decline to give.

Billing notes

  • Annual billing saves roughly ten percent against monthly on every tier, and there is no lock-in; plans can be upgraded or downgraded at any time.
  • Report volume counts all report types together, so a busy CSP deployment consumes the same allowance as DMARC reports, which matters if you use the web monitoring alongside email.
  • Retention is short: thirty days on Sand, Pebble, and Stone, ninety days on Mountain and Himalaya. Diagnosing a quarterly sending pattern is not possible on a thirty-day window.
  • Extra domains at $12 a month per pack of ten works out to $1.20 a domain, which is roughly a fortieth of what dmarcian's fifteen-domain tier costs per domain.
  • The one-month trial without a credit card is longer than the fourteen days most competitors offer and long enough to see a full monthly cycle.
  • There is no permanently free plan, though Sand at $1.25 a month is close enough for personal use.

Value assessment: On price per monitored domain, URIports is not merely the cheapest option in this category, it is cheaper by an order of magnitude. Twenty-five domains for $30 a month against dmarcian's fifteen for $600 is the kind of gap that demands an explanation, and the explanation is guidance: URIports gives you accurate reports and alerts, not a curriculum. Add the CSP, DNS, and certificate monitoring, which would otherwise be separate subscriptions, and a technical team that owns both mail and websites is getting several tools for the price of one. The two real costs are short retention and the absence of hand-holding. If you have the skills, this is the best value in the category by a wide margin.

Strengths & limitations

Strengths

  • By far the cheapest published per-domain pricing in the category: five domains for $6 a month, twenty-five for $30, a hundred for $120.
  • A published add-on domain price of $12 per pack of ten, where most competitors in this field refuse to quote per-domain costs at all.
  • Genuine breadth: DMARC, SMTP TLS reporting, hosted MTA-STS, DANE, DNS monitoring, certificate expiry, CSP, Reporting API, and Network Error Logging in one console.
  • Hosted MTA-STS policy serving removes the main practical obstacle to deploying MTA-STS at a small organization.
  • A full one-month trial with no credit card, long enough to observe a complete monthly sending cycle before committing.
  • No lock-in, with upgrades and downgrades available at any time.

Limitations

  • Very little guided remediation; URIports tells you accurately what is wrong and largely leaves the fixing to you, which will strand a first-time deployer.
  • Retention is short at thirty days on the lower tiers and ninety on the higher ones, against a year on comparable PowerDMARC and DMARCLY plans.
  • Report volume is pooled across DMARC, TLS, and browser report types, so heavy CSP use eats into the same allowance as email reporting.
  • No hosted SPF, DKIM, or DMARC record management, so SPF lookup overflow has to be fixed by hand rather than delegated as it can be with PowerDMARC or DMARCLY Safe SPF.
  • No vendor-by-vendor setup wizards, so identifying an unfamiliar sending source is a research task rather than a labelled row.
  • No inbox placement testing, so it cannot say whether mail landed in the inbox, promotions, or spam.
  • No warming capability, so a new sending domain or mailbox still needs a separate tool entirely.

Head-to-head comparisons

6 alternatives

URIports vs EasyDMARC

from $0 (Free, one domain), then $35.99 per month billed annually (Plus)

EasyDMARC costs roughly six times more for fewer domains and earns the difference through vendor naming, SPF flattening, and guided remediation aimed at people with no email background. URIports gives you accurate reports across far more domains and expects you to know what to do. Non-technical owners with one to four domains should take EasyDMARC; technical operators with more domains should take URIports.

Full URIports vs EasyDMARC comparison

URIports vs PowerDMARC

from $0 (Free), then Basic from around $8 per month by volume, about $12 per month billed annually at the 100,000-email step

PowerDMARC hosts your SPF, DKIM, DMARC, BIMI, and MTA-STS records and gives a year of history at roughly $12 to $15 for five domains, where URIports gives five domains for $6 with thirty days of retention and no record hosting beyond MTA-STS. Take PowerDMARC for managed records and longer history; take URIports for more domains, broader infrastructure monitoring, and a lower bill.

Full URIports vs PowerDMARC comparison

URIports vs dmarcian

from $0 (Personal, non-business use), then $24 per month (Basic)

dmarcian is the specification author's product, with the best documentation and diagnostic inspectors in the field, at $240 for eight domains and $600 for fifteen. URIports covers twenty-five for $30 and teaches you nothing. Choose dmarcian when the project is learning to do DMARC properly on a couple of domains; choose URIports when you already know how and need coverage at scale.

Full URIports vs dmarcian comparison

URIports vs DMARCLY

from $17.99 per month (Professional)

DMARCLY is the closest competitor on the value axis, with fifteen domains at $69 and two hundred at $199, plus Safe SPF and blacklist monitoring that URIports lacks. URIports is cheaper again and adds CSP, DNS, and certificate monitoring. Take DMARCLY for more email-specific tooling and longer history; take URIports if you own the websites too and want one bill for everything.

Full URIports vs DMARCLY comparison

URIports vs Red Sift OnDMARC

from $9 per month billed annually (Express)

OnDMARC Express at $9 a month for four domains hosts your SPF, DKIM, DMARC, MTA-STS, and BIMI records and comes from a well-funded security vendor, where URIports gives five domains for $6 with monitoring rather than record management. Take OnDMARC if you want records managed for you on a handful of domains; take URIports if you have many domains, own the websites too, and are happy managing your own DNS.

Full URIports vs Red Sift OnDMARC comparison

URIports vs GlockApps

from $59/mo (Essential, billed annually)

GlockApps sits on the placement testing side of the category with DMARC analytics bundled in, where URIports does authentication and infrastructure reporting with no placement testing at all. They answer different questions and are frequently confused. Buy GlockApps to find out where your mail lands; buy URIports to find out who sends as your domains and whether your records are intact.

Full URIports vs GlockApps comparison

Implementation & onboarding

Setup time
Fifteen to thirty minutes to add domains and publish reporting records, and about the same again to point CSP and TLS-RPT at it if you want the wider coverage. Reaching p=reject still takes weeks of calendar time regardless of the tool.
Learning curve
High relative to the guided competitors, and that is the deliberate trade for the price. URIports assumes you understand SPF alignment, DKIM selectors, and CSP directives, and will not walk you through any of them.
Onboarding
Entirely self-serve, with a one-month trial and no credit card required. Support is documentation-led, with a security specialist included only on the top tier.
Migration notes
Moving from another DMARC platform means repointing the rua tag; report history does not transfer between vendors, and URIports' short retention means the historical window is limited in any case. If you use hosted MTA-STS, leaving later means standing up your own policy endpoint before removing the delegation.

Platform, API & security

Platforms
Web applicationReport ingestion endpoints for DMARC, TLS-RPT, CSP, and the Reporting APIHosted MTA-STS policy endpoint
API
Not published as a headline self-serve feature; the platform is oriented around its own console and alerting rather than programmatic export.
Compliance
GDPR
Data residency
European operation; regional specifics are not published as a customer-selectable option.
SSO
OIDC single sign-on from the Mountain tier; team access from Stone.
Security notes
DMARC aggregate reports carry sending IPs and authentication outcomes rather than message bodies. Failure reports may include headers and, from some receivers, partial content, so enable ruf deliberately on sensitive domains. CSP and Reporting API endpoints receive data from visitors' browsers, which is worth reviewing against your own privacy policy before deployment.

Support & resources

Channels
Email supportSecurity specialist support on the Himalaya tier
Documentation
Practical technical documentation covering DMARC, TLS-RPT, MTA-STS, DANE, CSP, and the Reporting API, written for people who already work with this infrastructure.
Community
No large official community; the product is technical-documentation-led.

Company

Founded
2018
Headquarters
Netherlands
Ownership
Privately held, independent
Employees
Not disclosed; operates as a small independent team
Funding
No disclosed outside funding.

Timeline

  1. 2018Launches as a reporting endpoint for browser-generated Content Security Policy violations, built on the observation that infrastructure already emits telemetry nobody collects.
  2. 2019Extends the same report-collection model to email, adding DMARC aggregate and failure report ingestion alongside the browser reporting.
  3. 2021Adds SMTP TLS reporting, MTA-STS policy hosting, and DANE monitoring, covering transport security standards most small business tools ignore.
  4. 2023Adds DNS monitoring and certificate expiry watching, consolidating several separate monitoring subscriptions into one console.
  5. 2024The Google and Yahoo bulk sender requirements bring a wave of DMARC adoption, and URIports' per-domain pricing makes it the default choice for agencies watching large domain counts.

Integrations

  • DNS providers via published reporting and policy records
  • Google Workspace as a sending source
  • Microsoft 365 as a sending source
  • Hosted MTA-STS policy endpoint
  • Browser Content Security Policy and Reporting API endpoints
  • TLS-RPT reporting from sending mail servers
  • OIDC single sign-on providers from the Mountain tier

Frequently asked questions

10 questions

What is URIports?

URIports is a domain monitoring platform that collects reports your infrastructure already generates: DMARC aggregate and failure reports from mail receivers, SMTP TLS reports from sending servers, and Content Security Policy and Reporting API messages from visitors' browsers. It adds DNS, certificate, SPF, DKIM, and BIMI record monitoring and hosts MTA-STS policies.

Which of the three deliverability jobs does URIports do?

On the email side it does authentication monitoring: SPF, DKIM, and DMARC. It does not warm mailboxes and it does not run inbox placement tests. If your outbound is landing in spam while authenticating correctly, URIports will show clean authentication and nothing more; that problem belongs to a warming tool or a placement tester.

How much does URIports cost?

Sand is $1.25 a month for three domains and personal use. Pebble is $6 a month billed annually for five domains and 100,000 reports. Stone is $30 for twenty-five domains with DNS and certificate monitoring and team access. Mountain is $120 for a hundred domains with ninety-day retention and OIDC. Himalaya is $480 for four hundred domains. Every plan includes a one-month free trial with no credit card.

How many domains does each tier cover and what does an extra domain cost?

Three, five, twenty-five, one hundred, and four hundred across the five tiers. Extra domains are sold in packs of ten for $12 a month, which works out to $1.20 per domain. That published add-on price is unusual; most DMARC vendors in this category direct you to sales when you exceed a tier.

What are the report volume limits?

10,000 reports a month on Sand, 100,000 on Pebble, 500,000 on Stone, 2.5 million on Mountain, and 10 million on Himalaya. Importantly, the allowance is pooled across all report types, so a busy Content Security Policy deployment consumes the same budget as your DMARC reports. Email-only users will rarely trouble the limits.

Does URIports support hosted SPF, DKIM, and BIMI records?

It monitors SPF, DKIM, and BIMI records rather than hosting them, so you publish and maintain those in your own DNS and URIports alerts you when they change or break. The exception is MTA-STS, where URIports does host the policy endpoint on your behalf, which removes the main practical obstacle to deploying that standard. BIMI logo display at most large providers also requires a Verified Mark Certificate bought separately.

How are aggregate and failure reports presented to a non-expert?

Honestly, not especially gently. Aggregate reports become per-source views with SPF and DKIM alignment outcomes and clear alerting, which is accurate and readable if you already understand alignment. There are no vendor-by-vendor setup wizards and no named remediation steps. A buyer with no email background will get further with EasyDMARC or dmarcian even at several times the price.

How does URIports get me to a p=reject policy?

The same way any DMARC platform does, with less guidance. You publish p=none, watch the aggregate reports identify every source sending as your domain, authorize the legitimate ones in SPF and enable DKIM signing at each vendor, then tighten to p=quarantine with a percentage rollout and finally p=reject. URIports gives you the evidence and the alerts; it does not walk you through vendor configuration. Expect four to eight weeks of calendar time for a domain with several sending vendors.

Why is URIports so much cheaper than the DMARC specialists?

Because it sells report collection and monitoring rather than a guided deployment programme. dmarcian charges $600 a month for fifteen domains and includes documentation, inspectors, and optional deployment services; URIports covers twenty-five for $30 and includes accurate data. If you have the technical skills the gap is close to pure savings. If you do not, the cheaper tool can cost more in stalled projects.

Do I still need a warming tool or a placement tester?

If you send cold outbound or are starting a new domain, yes. Authentication is a prerequisite for good placement, not a substitute. A typical stack is URIports for authentication and infrastructure monitoring, a warming service such as MailReach or TrulyInbox for new mailboxes, and a placement tester such as GlockApps or Unspam for evidence of where mail actually lands.

Editorial verdict

URIports is the best value in this category if you have the technical competence to use it. Five domains for $6 a month and twenty-five for $30 is not a small discount against dmarcian or EasyDMARC, it is a different order of magnitude, and the breadth is real: DMARC, TLS reporting, hosted MTA-STS, DANE, DNS and certificate monitoring, and browser-side CSP collection in one console for less than the cost of a single competing subscription. The trade is explicit. Retention is short, there is no record hosting beyond MTA-STS, and there is essentially no guided remediation, so a small business owner encountering DMARC for the first time will stall where a more expensive tool would have carried them. Buy it if you are an engineer or an agency watching many domains. Buy something friendlier if this is your first DMARC deployment, and in either case do not expect it to say anything about inbox placement.

Written by the SaaSTracker editorial team. Awards, when shown, are judged against the published criteria in our methodology.