Email authentication infrastructure, delivered through API
Automate email authentication across every domain you manage. Built for enterprise security teams, MSPs, and wholesale partners.
90,000+ organizations trust EasyDMARC worldwide
Built for teams operating email authentication at scale.

Enterprise security teams
DMARC data into the SIEM, SOC, and GRC tools your security team already runs.
- Pull DMARC aggregate and failure reports into Splunk, Sentinel, or Datadog
- Discover and monitor third-party senders authorized for your domains
- Batch check DNS authentication records across all domains
- Retrieve DMARC failure reports with EML attachments for forensics

Managed service providers
Multi-tenant DMARC delivery across every client account from one API.
- Onboard client domains in bulk with batch domain endpoints
- Run DNS lookups across every domain on your account
- Pull DMARC aggregate and failure reports for any client
- Manage team access at the account level

Hosting providers and registrars
Sell DMARC as a billable add-on through your existing storefront.
- Run DMARC, SPF, and DKIM checks inside your customer tooling
- Onboard customer domains at scale with batch endpoints
- Build branded customer-facing reports on your stack
- Surface DMARC status inside your own customer-facing UI
74 endpoints across the DMARC stack.
Direct API access to DNS lookups, DMARC reports, and domain operations.
PUBLIC API / 64 ENDPOINTS ACROSS 5 CATEGORIES
Query, monitor, and manage authentication.
Record lookups across eleven DNS types, DMARC RUA aggregate report retrieval, RUF failure report retrieval with EML attachments, and domain lifecycle management.
PARTNER API / 10 ENDPOINTS ACROSS 2 CATEGORIES
Reseller and Wholesale operations
For Wholesalers and Resellers managing customer accounts at scale. Available to MSPs and MSSPs by agreement with our partner team.
What teams are building with it.
Concrete integration patterns in production across enterprise, MSP, and wholesale accounts.
SIEM data export
Pull DMARC report data into Splunk, Sentinel, or Datadog on a schedule.
Portfolio DNS audits
Batch check DMARC, SPF, DKIM, and BIMI records across every domain on a schedule.
Compliance reporting
Pull aggregate data into your BI layer for SOC 2 audit trails and board reporting.
Failure forensics
Retrieve RUF failure reports with EML attachments for incident investigation.
Compliance evidence
Pull DNS authentication snapshots into Jira, ServiceNow, or audit tooling.
Bulk domain onboarding
Import client domains at scale with a single batch call.
DMARC posture checks
Run DNS lookups against every client domain to verify DMARC, SPF, and DKIM records.
Client domain inventory
List, group, and search client domains added under your account.
Team access management
Invite, revoke, and update team members on your MSP account.
Per-client reporting
Pull DMARC aggregate data filtered by client domain for recurring reviews.
Failure report retrieval
Pull DMARC failure reports per client domain on a polling schedule.
Embedded portals
Surface DMARC posture inside your own customer-facing dashboard.
DNS health checks
Run DMARC, SPF, DKIM, and BIMI lookups inside your configuration tools.
Bulk provisioning
Onboard customer domains at scale with batch domain endpoints.
Branded reporting
Pull aggregate and failure data to build white-labeled customer reports.
Customer reporting feeds
Pull aggregate report data on schedule and surface it inside your customer portal.
What you can build with the API.
Three ways teams use EasyDMARC behind the scenes. Pick the one closest to your setup.
Send DMARC data into the security tools you already use
If your security team works in Splunk, Sentinel, or Datadog, DMARC reports can flow there automatically. No new dashboard to learn.
DMARC reports flow into the SIEM
DMARC reports for every one of your domains flow into Splunk, Sentinel, or Datadog automatically. The same place your security team already looks every day.
API ENDPOINTS
SIEM rules trigger SOC playbooks
When someone tries to impersonate your brand or send fraudulent email pretending to be you, your security tool catches it and opens a ticket in ServiceNow or Jira with the proof attached.
TRIGGERS
Audit-grade evidence on schedule
DMARC evidence for SOC 2, ISO 27001, NIS2, and DORA audits gets collected on schedule. When auditors ask for proof, the records are already there.
COMPLIANCE FRAMEWORKS
Run DMARC for all your clients from one place
Manage every client's domains under one EasyDMARC account. Onboarding, monitoring, and reporting happen automatically through your PSA.
Bulk client onboarding at deal close
When you sign a new client in your PSA, all their domains get added to EasyDMARC automatically and grouped under that client. No spreadsheets, no copy-paste.
API ENDPOINTS
Daily posture checks across every client
Every day, every client domain gets checked. If something breaks, a ticket opens in your PSA, tagged to the right client and routed to the right technician.
API ENDPOINTS
Per-client reporting from one data layer
Monthly reports and quarterly business reviews build themselves. Data flows into Power BI or your reporting tool. When a client asks why an email failed, the answer is one click away.
API ENDPOINTS
Sell DMARC inside the shop you already run
Add DMARC as a paid add-on in WHMCS, Blesta, or your storefront. When a customer buys, everything is set up for them automatically.
Customer buys, account goes live
A customer adds DMARC to their cart and pays. Their account opens, their domains get added, and a one-click link signs them into EasyDMARC. No support ticket needed.
API ENDPOINTS
Billing flows through the API
When a customer renews, upgrades, or cancels, EasyDMARC follows along. If they stop paying, the service pauses. When they pay again, it comes back. You do not have to do anything.
API ENDPOINTS
DMARC inside your customer portal
DMARC status shows up inside your customer portal, next to their hosting and domain info. They never need to log in to a second tool.
API ENDPOINTS
Two paths to API access
Enterprise and MSP accounts get API keys directly from the dashboard. Wholesalers and Resellers go through our partner team.

Enterprise & MSP accounts
Generate your API key directly from the Settings page in your EasyDMARC dashboard. No sales conversation required.

Wholesale & Resellers
Partner-tier API access is provisioned through our partner team. Contact us to discuss your distribution model.
Enterprise-grade by design.
API-specific signals for security and procurement review.
5-region data residency
Reports process in 5 AWS regions. The hostname in your DNS decides which region. No cross-region transfer.
Authentication & access controls
Bearer token per API key. Scoped permissions per partner and per environment. SAML 2.0 SSO at the platform with Okta, Microsoft Entra ID, and Google Workspace. Every API call is logged.
Stable API contract
Versioned endpoints. 12-month deprecation policy on stable endpoints. No surprise breaking changes. 99.9% uptime SLA backed by redundant infrastructure.
SOC 2 Type II + SOC 3 certified
Annual SSAE 18 audit by an independent third-party firm. ISO 27001-aligned operations. GDPR and CCPA compliant with DPA available. Annual third-party penetration testing.
Every endpoint documented. Always current.
Complete method references, parameter schemas, response examples, and error codes, updated as new endpoints ship.
How do I get an API key?
Enterprise and MSP accounts can generate API keys directly from the Settings page in the EasyDMARC dashboard. Wholesale and Reseller accounts get partner-tier API access provisioned through our partner team. Pass the key in every request using the Authorization: Bearer <token> header.
What is the base URL?
https://api.easydmarc.com, HTTPS only. The current version is v1.0, accessed at paths like /v1.0/dns/dmarc. HTTP requests are not supported.
Does the API support batch operations?
Yes. Batch endpoints cover all 11 DNS record types (A, AAAA, MX, NS, PTR, TXT, CNAME, DMARC, DKIM, SPF, BIMI) and domain creation. Use batch endpoints to reduce API calls and optimize against rate limits when querying multiple domains.
Does EasyDMARC have a DNS lookup API?
Yes. The DNS API runs lookups for 11 record types: A, AAAA, MX, NS, PTR, TXT, CNAME, DMARC, DKIM, SPF, and BIMI. Every record type supports single and batch lookups, so you can query one domain or thousands in a single workflow. PTR lookups cover reverse DNS.
Can I check a domain's DMARC record through the API?
Yes. Call /v1.0/dns/dmarc to retrieve a domain's DMARC record, or use the batch endpoint to check DMARC records across your whole portfolio. SPF, DKIM, and BIMI record checks work the same way through their own endpoints.
What authentication methods are supported?
Bearer token authentication per API key for all standard API calls. Pass the token in the Authorization header on every request.
How do MSPs use the API?
MSPs manage all client domains under a single MSP account. The Public API gives full access to onboarding domains in bulk, running DNS lookups, and pulling DMARC reports across the entire client base. Partner API access for multi-tenant operations is available to MSPs by agreement with our partner team.
Can I get DMARC aggregate report data as JSON instead of parsing XML?
Yes. EasyDMARC receives and parses raw RUA XML for you. The Aggregate Reports API returns that data as structured JSON, so you never need to build your own DMARC XML parser or reader. Pull the JSON into a SIEM, a data warehouse, or an internal dashboard.
Can I download DMARC failure report attachments via the API?
Yes. The Failure Reports API lets you retrieve individual failure reports, download the EML source, download specific attachments, or pull all attachments as a ZIP archive. Aggregated statistics across failure reports are also available.
How do I integrate DMARC reporting into a SIEM or internal dashboard?
Pull parsed aggregate (RUA) report data as JSON for SIEM ingestion, and retrieve failure (RUF) reports with EML attachments for SOC forensics. Both come through the same REST API with Bearer token authentication, JSON responses, and standard HTTP status codes.
Is the API rate limited?
Yes. API requests are rate limited per API key. Use batch endpoints when querying multiple domains to minimize request count. Exact rate limits are documented in the developer reference.
What response format does the API use?
All responses are returned in JSON. Successful responses include a data object and a meta object. Error responses include descriptive messages and standard HTTP status codes.
What is an email authentication API?
An email authentication API lets you check and monitor SPF, DKIM, DMARC, and BIMI records and pull authentication reporting into your own systems programmatically. The EasyDMARC Public API covers the full stack across 74 endpoints: DNS record lookups, DMARC aggregate and failure report data, and domain management.
Is the EasyDMARC API on GitHub?
Yes. The public API documentation repository lives at github.com/easydmarc/public-api-docs.
