Find out who is sending email as you.
Every receiving mail server on the internet will tell you which sources are sending mail claiming to be your domain — but only in compressed XML aggregate reports nobody has time to read. Hello SOC reads them, names every sender, and walks you from p=none to p=reject without breaking the mail your business runs on.
- →Aggregate (RUA) reports ingested automatically from any receiver
- →SPF and DKIM alignment tracked per sending source
- →A staged path to enforcement, measured at each step
- →Available standalone, or included with your managed SOC
The three stages, and why most domains stall
DMARC is not a switch you turn on. It is a staged rollout, and the stage that actually stops spoofing is the one almost nobody reaches.
- p=noneObserve
Your DNS record asks receivers to report but take no action. Nothing is blocked, nothing breaks. We start ingesting your aggregate reports and building the list of every source sending as your domain — your mail platform, your CRM, your invoicing tool, your marketing vendor, and anyone spoofing you.
- p=quarantineContain
Once the legitimate senders are identified and aligned on SPF or DKIM, unaligned mail starts going to spam instead of the inbox. We watch the reports through the change so a forgotten sender surfaces as a dip in aligned volume, not as a sales team telling you their mail vanished.
- p=rejectEnforce
Unaligned mail claiming to be you is refused outright at the receiving server. This is the only stage that actually stops someone spoofing your domain — and it is where most domains never arrive, because the first two stages were never measured.
What the dashboard shows you
Every sending source, named
Each source IP in your aggregate reports, resolved and grouped, with volume over time. This is the list you cannot build from your own mail server — it only exists in reports sent by receivers.
SPF and DKIM alignment, separately
A source can pass SPF authentication and still fail DMARC alignment. We track the raw auth result and the policy-evaluated alignment result independently, so the fix is obvious: SPF record, DKIM signing, or neither.
Published policy and coverage
The policy receivers actually saw — p, sp and pct — recorded per report. If someone changes your DNS record, the change shows up in the next reporting window.
Disposition applied
What receivers did with the mail: delivered, quarantined or rejected. This is your evidence that the policy is enforcing as intended rather than sitting inert.
Where this matters most
Banks and co-operative banks
Customers cannot tell a real message from a spoofed one, and a payment-fraud campaign run from your own domain is a regulatory conversation as much as a security one.
See the banks page →Colleges and schools
Fee-payment and admissions mail is a standing target, and the sender list is long — departments, portals, a bulk-mail vendor nobody documented.
See the colleges page →Hotels and retail groups
Booking confirmations and invoices carry payment instructions, which makes your domain worth impersonating.
See the hotels page →DMARC monitoring — questions we get
- What is DMARC, and why does p=none do nothing?
- DMARC is a DNS record that tells receiving mail servers what to do when a message claiming to be from your domain fails SPF and DKIM alignment. The policy value is the part that matters: p=none asks receivers only to report, so a spoofed message claiming to be your CFO still lands in the inbox. Only p=quarantine and p=reject change delivery. A domain sitting at p=none has visibility, not protection — which is why the aggregate reports it generates are worth reading rather than filtering away.
- What does Hello SOC actually do with my DMARC reports?
- We give you a mailbox to point your RUA address at, and from there it is automatic. Hello SOC polls the mailbox, unpacks the compressed XML aggregate reports that receivers send, and flattens every record into your dashboard — source IP, message volume, SPF and DKIM authentication results, the policy-evaluated alignment result for each, the policy that was published at the time, and the disposition receivers applied. Reports arrive from many receivers for many domains; each report is mapped to the right tenant by the domain in its published policy.
- Does DMARC monitoring generate alerts?
- No, and we would rather be straight about that. DMARC monitoring in Hello SOC is a reporting and visibility feature, not a live detection feed — aggregate reports arrive on a daily cycle from receivers, which is the wrong timebase for alerting on anything. Live email detection comes from a different source: your mail server authentication and anti-spam logs, which we ingest separately and which do raise alerts for SMTP brute-force, mail reconnaissance and phishing bursts.
- How long does it take to get from p=none to p=reject?
- For a straightforward domain with two or three sending services, six to eight weeks is realistic. Larger organisations with a long tail of departmental senders take longer, and that is a feature of the process rather than a delay — the whole point is to find every legitimate sender before enforcement starts breaking their mail. The pace is set by your reporting windows and how quickly sender owners can be tracked down internally, not by us.
- Do I need Hello SOC as my full SOC to get DMARC monitoring?
- No. DMARC monitoring is available on its own if email authentication is the only problem you are solving right now. It is also included at no extra cost when you run Hello SOC as your managed SOC, where it sits in the same dashboard as your firewall and server telemetry.
Not sure what your domain publishes today?
Send us your domain. We’ll check what SPF, DKIM and DMARC records you have live right now and tell you what a spoofer could do with them — no engagement required.