Threat Intelligence
What it is: a deep, on-demand security scan of a domain, going well beyond DMARC data, checking infrastructure, malware associations, and (where connected) third-party cyber-risk intelligence.
What you'll see: a Security Grade (A-F, with a 0-100 score), a Risk Level (low/medium/high), open ports found, and known CVEs affecting the domain's infrastructure. If a cyber-intelligence integration is connected, you'll also see a company profile, industry compliance-standard badges, and per-category domain ratings. Below that, always-on modules show malware-scan results, IP infrastructure (location, ISP, operating system), and a malware-feed reputation check.
Why use it: to answer "is this domain's infrastructure actually risky," not just "did this email pass DMARC."
Geo Intelligence
What it is: a world map plotting where your mail, and any spoofing attempts, actually originate, with a per-country breakdown of pass vs. fail volume.
What you'll see: a heatmap where circle size and color reflect fail volume (blue = low, amber = medium, red = high), a High Threat Regions list ranked by fail count, and summary stats for total countries seen and total threats. Use the This Domain / All Domains toggle at the top of the page to switch between the domain currently selected in the dashboard and a roll-up across every domain your organization owns.
Why use it: concentrations of failing traffic from a country you don't do business in are a fast, visual way to spot abuse you'd otherwise have to dig for in a table.
Bulk Senders (Compliance Monitor)
What it is: a check against Google, Yahoo, and Microsoft's bulk-sender requirements, the rules that determine whether high-volume senders land in the inbox or get throttled/blocked.
What you'll see: a Readiness Score out of 100, a per-provider verdict (Ready / At Risk for Google, Yahoo, and Microsoft separately, since each has slightly different requirements), and a checklist of exactly which requirements you meet and which are missing. It also includes a one-click Validator for the one-click unsubscribe headers (List-Unsubscribe / RFC 8058) that bulk-sender rules require.
Why use it: if you send any real volume of marketing or bulk mail, missing one of these requirements can throttle your entire domain's deliverability, not just the non-compliant messages.
ASM DNS Risk
What it is: attack-surface monitoring that watches for dangling DNS records, entries (usually CNAMEs) that still point at a service you no longer control, which an attacker can claim and use to send mail or host content as your domain.
What you'll see: a count of monitored records, how many are currently dangling, and DNSSEC/DANE status per record. A dangling record is clearly flagged with the exact CNAME target it points to, so you know precisely what to remove or reclaim.
Why use it: dangling DNS is one of the more overlooked ways a domain gets abused, it doesn't show up in DMARC reports at all until someone's already exploiting it.
App Security
What it is: a scan of your website's HTTP response headers, the security controls a browser relies on, not an email-specific check.
What you'll see: a security score (percentage of checked headers present) and a pass/fail for each of 7 headers: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options (all treated as critical), plus X-XSS-Protection, Referrer-Policy, and Permissions-Policy. Click into a domain for the full detail: which headers are missing with a suggested fix, which are present with their actual value, and the complete raw response for reference.
Why use it: email authentication protects your mail; this protects your website from clickjacking, MIME-sniffing, and related browser-level attacks.
SMTP Security
What it is: a check of your mail servers' SMTP configuration, specifically whether they support STARTTLS for encrypted delivery.
What you'll see: how many of your mail servers have STARTTLS confirmed active, with an "Active" or "Not Supported" badge per server, and the negotiated TLS version. A server DMARCS hasn't been able to check yet (no MX found, still pending, or the check failed) is shown as "not checked" rather than counted as a failure, so a scan-in-progress domain doesn't look artificially insecure. Expand a row to see the individual MX records behind it, each with its own location and provider (e.g. Google Workspace, Microsoft 365).
Why use it: pairs with TLS Reports, this tells you whether your own outbound mail servers are configured correctly, rather than whether inbound TLS reports about you look healthy.
Certificate Monitor
What it is: tracks SSL/TLS certificates for your monitored hosts and warns before they expire.
What you'll see: a grade (A/B/C, or red for anything worse) per host, issuer, protocol and cipher in use, and a validity progress bar. A host that hasn't finished its first scan shows Pending Scan, not expired, so a brand-new host never looks like a problem it isn't. A certificate is flagged Expiring Soon once it has fewer than 30 days left.
Why use it: an expired certificate on a mail-adjacent host can break delivery or trigger browser warnings with no other warning sign.
Risk Explorer
What it is: automated lookalike/typosquat domain detection. It continuously scans for domains registered to impersonate yours (you may see this page titled "Lookalike Monitoring" once you're in it).
What you'll see: every one of your domains is scanned automatically, with a count of lookalikes found and a risk level (Low/Medium/High, scaled by how many were found). Expand any domain to see the individual lookalike domains detected, tagged with the technique used to generate them (e.g. a homoglyph swap or a bit-level typo).
What you can do about one: click Analyze for a live check, is the lookalike domain actually online, does it have its own SPF/DMARC, is it weaponized enough to be a real risk, or click Takedown to submit a takedown request to DMARCS's team for review.
SubdoMailing Guard
What it is: detects subdomain-takeover exposure, DNS records (dangling MX, broken SPF, or dangling CNAME) that attackers can claim and then send mail from your own subdomain, bypassing your main domain's DMARC policy entirely.
What you'll see: a count of active vulnerabilities broken down by type, plus a table of exactly which record is exposed and what service it points to. Since these records live in your own DNS zone, DMARCS can't fix them for you, each row has a Copy Record to Remove button that copies the exact record to your clipboard so you can delete it at your DNS provider.
Why use it: this is the specific mechanism behind "subdomain spoofing," a scale of abuse that regular DMARC monitoring on your main domain won't catch.
Subdomain Monitor
What it is: discovers your subdomains and checks each one's DMARC protection, catching unprotected subdomains attackers commonly abuse.
What you'll see: total subdomains found, how many were discovered today, and a table with first-seen/last-seen dates for each. Click Inspect Details on any subdomain to jump straight into DNS Inspector, pre-loaded and ready to run for that exact subdomain.
Why use it: a forgotten subdomain with no DMARC record of its own is a gap in your protection even if your main domain is fully locked down.
Vendor Risk
What it is: third-party risk management for the vendors sending email on your behalf, your digital supply chain.
How to use it: click Auto-Discover to have DMARCS scan your SPF includes and detected mail infrastructure for vendors automatically, or add one yourself with Watch Vendor.
What you'll see per vendor: a security grade or risk score, a "High Risk" flag if breach history exists, and at-a-glance security status for DMARC policy, SPF, MTA-STS, and BIMI. Click into any vendor for the full picture: company profile, industry compliance standards, an 8-category security-posture breakdown (application security, network security, DNS health, email security, patching cadence, IP reputation, web encryption, and public mentions of hacktivist activity), breach/ransomware history, and a supply-chain table showing any vendors that vendor in turn relies on.
Why use it: your DMARC policy is only as trustworthy as the vendors you've authorized to send on your behalf; this tracks their security posture over time, not just at the moment you added them.