Aggregate reports from the mailbox providers that already grade your mail
The same onboarding you'd do by hand — we just do the parsing, the sender identification, and the policy changes for you.
Type your domain and we mint a private token for its reports. No account plumbing, no verification email loop.
Hosted setup: point a single CNAME at us and we serve the DMARC policy for you. Prefer classic? Paste a TXT instead. Hit Check DNS and we confirm it's live.
Mailbox providers start sending aggregate reports. The dashboard fills in and walks you from p=none to quarantine to reject — each step is a button, not a DNS edit.
Publish one CNAME once and policy changes become dashboard buttons — p=, pct=, sp= all handled for you. After that you never touch DNS again.
Competitors gate this at ~$72/mo, or don't offer it.Invite your whole team — admins who change policy, members who just read the reports. Seats are never a line item here.
Others start at a single user per account.The free tier is the trial — permanent, no 14-day clock, and real business use is welcome. Upgrade only when you outgrow the volume.
Not a countdown trial. No non-commercial restriction.Every source is enriched with geolocation, network owner and threat flags — Tor exits, known attackers, abusers — so an unknown sender usually explains itself. How to read the flags →
Typically a paid security add-on elsewhere.We re-check your DMARC, SPF, MX and DKIM records every day and email you the diff when anything changes. The quietly edited record is how spoofing comes back after p=reject. Why records drift →
On every plan. Nothing to configure.Legitimate mail passes SPF or DKIM aligned to your domain. Anything failing both is either a service nobody configured — or someone spoofing you. We identify the source, count the messages, and surface it at the top so you know exactly what enforcing p=reject will block. And every IP arrives with intelligence attached — where it is, who owns the network, whether it's flagged infrastructure — so an unknown row usually explains itself.
bounce.mailerz.runorthwind.coDMARC is a DNS record that tells mailbox providers what to do with mail claiming to be from your domain that fails authentication (SPF and DKIM): monitor it (p=none), quarantine it, or reject it. Providers send you aggregate reports on what they saw. The catch is those reports are dense XML from dozens of senders — Canny Pigeons parses them, identifies each source, and shows you when it's safe to tighten the policy.
Aggregate statistics only — sending IP addresses, message counts, and pass/fail results for SPF and DKIM. We never see message content: no subjects, no bodies, no recipients. DMARC aggregate reports simply don't contain them.
We enrich every source IP against commercial geolocation and threat-intelligence feeds: country and city, network owner (ASN), and flags like Tor exit node, VPN, known attacker or known abuser. It's on every plan, including Free, with nothing to configure. Treat flags as evidence rather than verdicts — mail that passes DMARC from a VPN-flagged IP is usually just a teammate on a VPN.
The first aggregate reports usually arrive 24–48 hours after you publish the record, because providers batch and send them on their own schedule (typically daily). After that the dashboard updates as new reports come in.
Anytime, from the billing screen. Downgrading to Free keeps your monitoring running within the free limits — nothing gets deleted out from under you, and you can re-upgrade whenever you like.
One domain, unlimited teammates, no card. See pricing →