Common causes: a third-party service isn't in your SPF record, a missing DKIM signature, a misaligned From address, or forwarded email (expected behavior).
Typically 24–48 hours after publishing your DMARC record.
p=none is monitoring mode: failing email is still delivered, but you receive reports.When all legitimate senders are identified, they pass SPF and/or DKIM, you've monitored for 2–4 weeks, and alignment is above ~95%.
Get the SPF include from the provider's docs, add it to your SPF record (Smart SPF can do this for you), enable DKIM signing, then monitor for 1–2 weeks before moving on.
SPF checks whether the sending IP is authorized. DKIM checks a cryptographic signature and survives forwarding. Use both for the best protection.
Not currently. The only outbound chat/ticketing integrations today are Microsoft Teams and ConnectWise PSA (see Organisation → Integrations).
Pull DMARC report data, domain security scores, vendor risk data, audit logs, and generate PDF reports programmatically, or stream events into a SIEM. See Public API for the full list and rate limits.
DMARCS runs two independent regional deployments, one serving the EU and one serving the UAE, each with its own hosting, database, and mail processing. Your data stays in the region your account is hosted in. See the Trust Center's Security page for the full detail on encryption, access control, and audit logging.