DMARC monitoring, minus the busywork

See who sends mail as your domain — and stop the spoofers.

Point one DNS record at Canny Pigeons and we turn the flood of DMARC reports into a clear dashboard — then walk your domain from p=none to p=reject, one button at a time.

Instant and free, no signup — DMARC, SPF and DKIM graded in seconds. Or start monitoring free →

app.cannypigeons.com/northwind.co Last 30 days
Compliance
96.4%
COMPLIANT
Total volume
842,193 +4.1%
Messages seen this month
Unknown senders
2 watch
Failing SPF and DKIM
SenderMessagesSPFDKIMDisposition
Google Workspace209.85.220.41512,340passpassnone
Mailchimp198.2.128.1584,210passpassnone
Amazon SES54.240.8.309,640passfailnone
Unknown — flagged185.234.71.9 · known attacker12,408failfailreject

Aggregate reports from the mailbox providers that already grade your mail

GoogleMicrosoft 365YahooComcastMail.ruFastmail
How it works

Three steps. One of them is DNS.

The same onboarding you'd do by hand — we just do the parsing, the sender identification, and the policy changes for you.

1 ≈ 30 seconds

Add your domain

Type your domain and we mint a private token for its reports. No account plumbing, no verification email loop.

northwind.co
2 One record, once

Publish one DNS record

Hosted setup: point a single CNAME at us and we serve the DMARC policy for you. Prefer classic? Paste a TXT instead. Hit Check DNS and we confirm it's live.

_dmarc CNAME → verified ✓
3 24–48 hours

Reports appear — we take it from there

Mailbox providers start sending aggregate reports. The dashboard fills in and walks you from p=none to quarantine to reject — each step is a button, not a DNS edit.

p=none → p=reject
Why Canny Pigeons

The things other tools charge extra for, or don't do at all.

Hosted DMARC, in the free tier

Publish one CNAME once and policy changes become dashboard buttons — p=, pct=, sp= all handled for you. After that you never touch DNS again.

Competitors gate this at ~$72/mo, or don't offer it.

Unlimited users, every plan

Invite your whole team — admins who change policy, members who just read the reports. Seats are never a line item here.

Others start at a single user per account.

Free forever, business allowed

The free tier is the trial — permanent, no 14-day clock, and real business use is welcome. Upgrade only when you outgrow the volume.

Not a countdown trial. No non-commercial restriction.

Threat intel on every IP

Every source is enriched with geolocation, network owner and threat flags — Tor exits, known attackers, abusers — so an unknown sender usually explains itself. How to read the flags →

Typically a paid security add-on elsewhere.
Δ

Daily DNS drift alerts

We re-check your DMARC, SPF, MX and DKIM records every day and email you the diff when anything changes. The quietly edited record is how spoofing comes back after p=reject. Why records drift →

On every plan. Nothing to configure.
Spot the spoofers

Every sender, graded. The spoofers stand out immediately.

Legitimate mail passes SPF or DKIM aligned to your domain. Anything failing both is either a service nobody configured — or someone spoofing you. We identify the source, count the messages, and surface it at the top so you know exactly what enforcing p=reject will block. And every IP arrives with intelligence attached — where it is, who owns the network, whether it's flagged infrastructure — so an unknown row usually explains itself.

  • Sender names resolved from IPs — Google, SES, Mailchimp and ~50 more, not raw addresses.
  • SPF, DKIM and disposition on one row.
  • Expand any row for envelope/header-from, location, network owner and alignment detail.
  • Threat flags built in — Tor exit nodes, VPNs, known attackers and abusers are labelled automatically.
SenderMessagesSPFDKIMDisposition
Google Workspace209.85.220.41512,340passpassnone
Unknown45.83.122.1918,204failfailquarantine
Envelope frombounce.mailerz.ru
Header fromnorthwind.co
Location🇷🇺 Moscow, Russia
NetworkBulletproof Hosting LLC (AS64496) · hosting
Threat intelKnown attacker · Threat-listed
NoteFails both from flagged infrastructure — spoofing; p=reject stops it
Unknown103.42.90.76,120failfailquarantine
SendGrid149.72.126.403,180passfailnone

Questions, answered plainly

What is DMARC, in one paragraph?

DMARC is a DNS record that tells mailbox providers what to do with mail claiming to be from your domain that fails authentication (SPF and DKIM): monitor it (p=none), quarantine it, or reject it. Providers send you aggregate reports on what they saw. The catch is those reports are dense XML from dozens of senders — Canny Pigeons parses them, identifies each source, and shows you when it's safe to tighten the policy.

What data do you actually see?

Aggregate statistics only — sending IP addresses, message counts, and pass/fail results for SPF and DKIM. We never see message content: no subjects, no bodies, no recipients. DMARC aggregate reports simply don't contain them.

Where does the IP intelligence come from?

We enrich every source IP against commercial geolocation and threat-intelligence feeds: country and city, network owner (ASN), and flags like Tor exit node, VPN, known attacker or known abuser. It's on every plan, including Free, with nothing to configure. Treat flags as evidence rather than verdicts — mail that passes DMARC from a VPN-flagged IP is usually just a teammate on a VPN.

How long until I see data?

The first aggregate reports usually arrive 24–48 hours after you publish the record, because providers batch and send them on their own schedule (typically daily). After that the dashboard updates as new reports come in.

Can I cancel or downgrade?

Anytime, from the billing screen. Downgrading to Free keeps your monitoring running within the free limits — nothing gets deleted out from under you, and you can re-upgrade whenever you like.

Start free

One domain, unlimited teammates, no card. See pricing →