Alerting: get an email when something changes
You won't look at the dashboard every day. Alerts are how DMARCS taps you on the shoulder when something actually needs you.
- Where to find it
- Organization → Alerting
Create an alert
- Click New Alert and give it a name.
- Pick a trigger type
Some triggers need a threshold; the rest fire on the event itself.
Trigger Fires when Threshold Auth Rate Drop Your DMARC pass rate falls below a percentage 1 to 100% Volume Spike Mail volume jumps by more than a percentage 1 to 1000% Cert Expiry A monitored certificate has fewer than N days left 1 to 365 days New Forwarder Detected A new forwarding source appears None DNS Record Change One of your monitored DNS records changes None Blacklist Hit One of your sending IPs lands on a blacklist None DMARC Downgrade Your policy is loosened (for example reject → none) None MTA-STS Broken Your MTA-STS policy stops resolving None SPF Lookup Limit Your SPF record approaches the 10-lookup ceiling None New Subdomain A subdomain you haven't seen before appears None - Save
Your alerts are listed under the form with their trigger, threshold and when they last fired (or "Never Triggered"). Edit or delete any of them there.
Where alerts go
Alerts are sent by email. There is no per-alert channel choice. To also post them into a chat channel or open a ticket, set up the Microsoft Teams or ConnectWise PSA integration.
Two alerts worth creating on day one: DMARC Downgrade, so nobody quietly weakens your policy, and SPF Lookup Limit, so you hear about a record creeping toward the ceiling before mail starts failing.
Still need a hand?
Email support@dmarcs.com, call +971 4 240 4441, or open a ticket from Support inside the app.