Public API

What you can get from the API

Anything you can see in the app, you can pull programmatically, plus a purpose-built event feed for security tooling.

AreaWhat it returns
Domain inventoryYour primary and monitored domains
DMARC reportingRaw aggregate report rows (source IP, disposition, SPF/DKIM results, counts) for one domain or all, up to 1,000 rows per call
PDF reportsGenerate and download an Executive or Technical report for a date range
Domain securityA live SPF and DMARC check plus a 0 to 100 security score for a domain you own
Vendor riskRisk and threat scores, DMARC policy and SPF status for each known sending vendor
Brand protectionLookalike and typosquat domain risk data
Audit logsYour organisation's audit trail, up to 100 rows per call
SIEM feedA cursor-paginated event stream for piping into a SIEM such as FortiSIEM. Needs a SIEM-scoped key.
Every data export through the API is itself written to your Audit Logs, including which key was used. Pulling data by API is as traceable as doing it in the app.

Full endpoint reference

Every endpoint, parameter and response format is in the interactive OpenAPI reference: admin.dmarcs.com/api/swagger/index.html (use admin-ae.dmarcs.com if your account is hosted in the UAE region). All calls go to /api/public_api.php on the same host you log in to.

Still need a hand?

Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.

Contact Support