InboxAuth scans your domain's SPF, DKIM, and DMARC records, then walks you through
a guided setup to close the gaps:
- DNS Scan — checks your current SPF, DKIM, and DMARC records.
- Connect Mailbox — validates an IMAP connection to a
reports@yourdomain.com
mailbox that will receive DMARC aggregate reports.
- Set DMARC — walks you through publishing a starter DMARC record
(
p=none, rua=mailto:reports@yourdomain.com) so reports start flowing in.
- Observer Mode — runs a 48-hour window, then automatically parses every DMARC
aggregate report received via IMAP to build a list of everyone sending mail as
your domain.
- Generate Records — once you've confirmed which senders are legitimate, generates
a tailored SPF record plus a DMARC record with your choice of
quarantine or
reject enforcement, and validates both live via DNS.
The Dashboard gives an at-a-glance view of SPF/DKIM/DMARC status, an overall Email
Security Score, a one-click re-scan, and a link to test whether your domain can
currently be spoofed via the companion Email Authenticity Checker tool.
Requirements
- PHP's
imap extension enabled (for Step 2 / Step 4 mailbox access)
- PHP's
zip extension enabled (Step 4 unpacks .zip-attached DMARC reports)
- Outbound DNS resolution available to the server (standard on virtually all hosts)