Spoofless

DMARC monitoring & email authentication

Know exactly who’s sending email as your domain.

Spoofless turns raw DMARC reports into plain-English answers: which senders are legit, which need a quick fix, and which are spoofing you — plus a safe, guided path to a policy that blocks impersonation for good.

One DNS record to set up. Nothing about your mail flow changes.

Illustrative example — your dashboard shows your domain’s real senders.

The problem

Spoofing is your problem — even if you never see it

DMARC solves it, but the tooling assumes you're an email-authentication expert. That's the gap Spoofless closes.

Anyone can send as you

Until DMARC is enforced, spammers can put your exact domain in the From line — phishing your customers, partners, and staff with your name on it.

The reports are unreadable

Once you ask for them, mailbox providers will send you the evidence — as daily XML files full of bare IP addresses. Almost nobody can turn that into a decision.

Enforcing blindly breaks your own mail

Jump straight to a strict policy and your invoices, newsletters, and support replies can start landing in spam. So most domains stay stuck at “monitoring” forever.

How it works

Three steps from “no idea” to enforced

  1. 01

    Publish one DNS record

    Point your domain's DMARC rua= address at Spoofless. It's a single TXT record — we hand you the exact value to paste — and it changes nothing about how your mail is delivered.

  2. 02

    Providers report to us

    Google, Microsoft, Yahoo and other mailbox providers start sending us daily aggregate reports about everyone claiming to send as your domain. We parse, deduplicate, and enrich them automatically.

  3. 03

    You get answers, not XML

    Every sender shows up named and triaged — green, amber, or red — with a plain-English fix where one is needed, and a Policy Advisor that tells you when it's safe to tighten enforcement.

Features

Built to hand you decisions

Two ideas carry the whole product — triage and the Advisor. Everything else exists to support them.

Hero feature

Traffic-light triage

Every sending source is classified into one of three states — the same three colors, everywhere in the product. One glance tells you what matters.

  • Authorized. Legit and correctly configured — Google Workspace, your ESP, your CRM. Leave them alone.

  • Needs fix. Legit but misconfigured — a tool sending real mail that isn’t aligned yet. These are the ones blocking enforcement.

  • Threat. Unknown infrastructure sending as your domain. This is what a tighter policy shuts down.

Hero feature

Policy Advisor

The scary part of DMARC is tightening the policy. The Advisor watches your alignment and tells you — with a clear verdict — when it’s safe to move from p=none to quarantine to reject, and hands you the exact record to paste when it is.

The key idea: your readiness is computed on legitimate mail only. Spoofers are supposed to fail authentication — so they never hold you back from enforcing.

See who's sending as you

Sources are named and enriched — Google, SendGrid, Mailchimp, “Unknown · hosting provider” — with volume and pass/fail per sender. Not a wall of raw IPs.

Every diagnosis ships with a fix

Each flagged sender comes with what's wrong and exactly what to click to fix it, in plain English — down to the vendor settings screen.

Protect your brand & deliverability

Enforcement blocks impersonation of your domain, and a clean, aligned setup is what mailbox providers increasingly require to keep you out of spam.

Teaches as you go

Alignment? Disposition? rua? Every piece of jargon has a hover explainer written for humans. You'll come out understanding DMARC, not just passing it.

Why Spoofless

Decisions, not just data

Most DMARC tools show you authentication results and stop. Spoofless is built around the three questions you actually have: am I okay, what do I fix, and when can I enforce?

Typical DMARC tools

Spoofless

Tables of IP addresses and auth results

Named senders, triaged green / amber / red

“SPF fail” and a link to an RFC

“Intercom's DKIM isn't aligned — here's the settings screen to fix it”

Charts you must interpret yourself

A verdict: safe to enforce, fix these first, or hold

Built for IT admins, small-business owners, and MSPs who know they “should do DMARC” — without needing to become email-authentication experts first.

Find out who’s sending as your domain

One DNS record and the reports start flowing. Your first plain-English picture of your domain’s email typically appears within a day or two.