Questions · Updated 2026-09-27
How do I set up DMARC for my sending domain?
Set up DMARC for your sending domain by publishing the TXT record GET /domains/{id} lists on _dmarc.yourdomain.com. It is recommended rather than required, POST /domains/{id}/verify confirms it resolved, and GET /deliverability/dmarc reads the aggregate reports the record asks receivers to send.
Set up DMARC for your sending domain by publishing the DMARC row from GET /domains/{id} or GET /domains/{id}/setup: a TXT record on _dmarc.<domain> whose value is v=DMARC1; p=none; rua=mailto:dmarc@reports.agentisend-dns.com. The record is recommended rather than required, so the domain verifies and sends without it. Publish it anyway: the rua address is where receivers mail their aggregate reports, and GET /deliverability/dmarc is where you read them.
The record
The DMARC row in the DNS sheet has host _dmarc relative to your zone (_dmarc.notify when the sending domain is notify.example.com and the zone is example.com), type TXT, and the value above. Its status starts as recommended and its required flag is false. The fix text on that row says: "Recommended, not required — the domain verifies and sends without it. Publish it to start receiving aggregate reports about mail sent in your name, then move from p=none to quarantine once the reports are clean."
Paste host and value at your DNS provider, then call POST /domains/{id}/verify. Any published DMARC policy counts as present; the check does not demand our exact string, because the policy is yours. Reports reach GET /deliverability/dmarc through the rua address in our value, so a record that names a different rua verifies and sends its reports elsewhere.
curl -sS -X GET https://api.agentisend.com/deliverability/dmarc \
-H "Authorization: Bearer $AGENTISEND_API_KEY"200
{
"alignment_failure_threshold": 1,
"days": [],
"sources": [],
"window_days": 1
}Reading the reports
GET /deliverability/dmarc takes domain and window_days. Its summary: "Aggregate authentication reports for your domains. Aligned and failing volume per day, and every address sending as you, flagged when it is not one of ours." The response has days, one row per day and domain with aligned, failing, failure_rate and total, and sources, one row per sending address with source_ip, message_count, aligned, failing, last_seen_day and ours. alignment_failure_threshold is the share of a day's volume failing alignment above which the failures count as a fault rather than noise.
A source with ours: false is another system sending as your domain: a marketing tool, a help desk, a forgotten server, or someone who is not you. Each one needs a decision before the policy tightens, because a stricter policy applies to that mail too.
Tightening the policy
p=none asks receivers to report and change nothing. p=quarantine asks them to treat failing mail as suspect. p=reject asks them to refuse it. Move one step at a time, and only when the reports are clean: every ours: false source is either authorised in your SPF and DKIM or confirmed as not yours, and your own sources show no failing volume. Edit the value at your DNS provider; GET /domains/{id} shows the new value under observed after the next check.