Reject forged DMARC reports before you parse them.
A free, confidence-scored allowlist of the systems that legitimately send DMARC aggregate (RUA) reports — built from transport evidence, not the report contents.
The allowlist is still being built — most IPs return "not recognized yet." See why below.
Reject forged or poisoned RUA reports at the connection layer, before anything parses them.
We're in data-discovery mode. Every reporting domain sharpens the model and gets us to a published list faster.
No cost, no catch. We never read or store your report contents — only the sender's connection metadata.
Prove control with a DNS record; we issue two RUA addresses to point your DMARC rua= at.
As reports arrive we record the sending server's transport evidence (IP, TLS, DKIM, FCrDNS) — never the XML.
Cross-domain, transport-authenticated senders earn confidence — the basis of the published allowlist.
The DMARC report XML is discarded unread — never parsed, never stored. We characterize only the sending server's connection.
Read the full transparency statement →