Back to Top
A new era for email starts now. Meet EasyDMARC V3. See what’s new →
Public API · v1.0

Email authentication infrastructure, delivered through API

Automate email authentication across every domain you manage. Built for enterprise security teams, MSPs, and wholesale partners.

Recognized as a Leader by Experts

Compliant with Industry Standards

90,000+ organizations trust EasyDMARC worldwide

Who it's for

Built for teams operating email authentication at scale.

Enterprise security teams

Enterprise security teams

DMARC data into the SIEM, SOC, and GRC tools your security team already runs.


  • Pull DMARC aggregate and failure reports into Splunk, Sentinel, or Datadog
  • Discover and monitor third-party senders authorized for your domains
  • Batch check DNS authentication records across all domains
  • Retrieve DMARC failure reports with EML attachments for forensics
Managed service providers

Managed service providers

Multi-tenant DMARC delivery across every client account from one API.


  • Onboard client domains in bulk with batch domain endpoints
  • Run DNS lookups across every domain on your account
  • Pull DMARC aggregate and failure reports for any client
  • Manage team access at the account level
Hosting providers and registrars

Hosting providers and registrars

Sell DMARC as a billable add-on through your existing storefront.


  • Run DMARC, SPF, and DKIM checks inside your customer tooling
  • Onboard customer domains at scale with batch endpoints
  • Build branded customer-facing reports on your stack
  • Surface DMARC status inside your own customer-facing UI
API surface

74 endpoints across the DMARC stack.

Direct API access to DNS lookups, DMARC reports, and domain operations.

PUBLIC API / 64 ENDPOINTS ACROSS 5 CATEGORIES

Query, monitor, and manage authentication.

Record lookups across eleven DNS types, DMARC RUA aggregate report retrieval, RUF failure report retrieval with EML attachments, and domain lifecycle management.

DNS Lookup 31 Aggregate Reports 7 Failure Reports 6 Domains 18 Authentication 2

PARTNER API / 10 ENDPOINTS ACROSS 2 CATEGORIES

Reseller and Wholesale operations

For Wholesalers and Resellers managing customer accounts at scale. Available to MSPs and MSSPs by agreement with our partner team.

Organizations 5 Users 5

What teams are building with it.

Concrete integration patterns in production across enterprise, MSP, and wholesale accounts.

Enterprise MSP / MSSP Wholesale / Resellers
SIEM data export

Pull DMARC report data into Splunk, Sentinel, or Datadog on a schedule.

Portfolio DNS audits

Batch check DMARC, SPF, DKIM, and BIMI records across every domain on a schedule.

Compliance reporting

Pull aggregate data into your BI layer for SOC 2 audit trails and board reporting.

Failure forensics

Retrieve RUF failure reports with EML attachments for incident investigation.

Compliance evidence

Pull DNS authentication snapshots into Jira, ServiceNow, or audit tooling.

Bulk domain onboarding

Import client domains at scale with a single batch call.

DMARC posture checks

Run DNS lookups against every client domain to verify DMARC, SPF, and DKIM records.

Client domain inventory

List, group, and search client domains added under your account.

Team access management

Invite, revoke, and update team members on your MSP account.

Per-client reporting

Pull DMARC aggregate data filtered by client domain for recurring reviews.

Failure report retrieval

Pull DMARC failure reports per client domain on a polling schedule.

Embedded portals

Surface DMARC posture inside your own customer-facing dashboard.

DNS health checks

Run DMARC, SPF, DKIM, and BIMI lookups inside your configuration tools.

Bulk provisioning

Onboard customer domains at scale with batch domain endpoints.

Branded reporting

Pull aggregate and failure data to build white-labeled customer reports.

Customer reporting feeds

Pull aggregate report data on schedule and surface it inside your customer portal.

What you can build with the API.

Three ways teams use EasyDMARC behind the scenes. Pick the one closest to your setup.

Enterprise SOC + GRC MSP / MSSP Service delivery Wholesale / Resellers Channel ops

Send DMARC data into the security tools you already use

If your security team works in Splunk, Sentinel, or Datadog, DMARC reports can flow there automatically. No new dashboard to learn.

Splunk ServiceNow Okta Cribl
01. Observe
DMARC reports flow into the SIEM

DMARC reports for every one of your domains flow into Splunk, Sentinel, or Datadog automatically. The same place your security team already looks every day.


API ENDPOINTS

GET /aggregate-reports GET /failure-reports GET /failure-reports/{id}/eml
02. Access
SIEM rules trigger SOC playbooks

When someone tries to impersonate your brand or send fraudulent email pretending to be you, your security tool catches it and opens a ticket in ServiceNow or Jira with the proof attached.


TRIGGERS

SOAR webhook SIEM correlation rule SLA-bound MTTR
03. Control
Audit-grade evidence on schedule

DMARC evidence for SOC 2, ISO 27001, NIS2, and DORA audits gets collected on schedule. When auditors ask for proof, the records are already there.


COMPLIANCE FRAMEWORKS

SOC 2 Type II ISO 27001 NIST CSF 2.0 DORA
OPERATIONAL OUTCOME

DMARC stops being a side project. Your security team monitors it the same way they monitor everything else, with the same tools and the same alerts.

Run DMARC for all your clients from one place

Manage every client's domains under one EasyDMARC account. Onboarding, monitoring, and reporting happen automatically through your PSA.

ConnectWise HaloPSA Autotask Power BI
01. Onboard
Bulk client onboarding at deal close

When you sign a new client in your PSA, all their domains get added to EasyDMARC automatically and grouped under that client. No spreadsheets, no copy-paste.


API ENDPOINTS

POST /domains/batch POST /domain-groups GET /domains/{id}/setup
02. Operate
Daily posture checks across every client

Every day, every client domain gets checked. If something breaks, a ticket opens in your PSA, tagged to the right client and routed to the right technician.


API ENDPOINTS

POST /dns/dmarc/batch POST /dns/spf/batch POST /dns/dkim/batch
03. Report
Per-client reporting from one data layer

Monthly reports and quarterly business reviews build themselves. Data flows into Power BI or your reporting tool. When a client asks why an email failed, the answer is one click away.


API ENDPOINTS

GET /aggregate-reports?domain_group= GET /failure-reports?domain=
OPERATIONAL OUTCOME

DMARC turns into a service line you actually bill for. Onboarding takes one click instead of an afternoon. Reporting runs on its own. Incidents land in the PSA your team already uses.

Sell DMARC inside the shop you already run

Add DMARC as a paid add-on in WHMCS, Blesta, or your storefront. When a customer buys, everything is set up for them automatically.

WHMCS Blesta WiseCP Pax8
01. Activate
Customer buys, account goes live

A customer adds DMARC to their cart and pays. Their account opens, their domains get added, and a one-click link signs them into EasyDMARC. No support ticket needed.


API ENDPOINTS

POST /partner/organizations POST /partner/subscriptions POST /auth/magic-link
02. Bill
Billing flows through the API

When a customer renews, upgrades, or cancels, EasyDMARC follows along. If they stop paying, the service pauses. When they pay again, it comes back. You do not have to do anything.


API ENDPOINTS

PATCH /partner/subscriptions/{id} POST /partner/subscriptions/{id}/cancel POST /partner/subscriptions/{id}/renew
03. Embed
DMARC inside your customer portal

DMARC status shows up inside your customer portal, next to their hosting and domain info. They never need to log in to a second tool.


API ENDPOINTS

GET /aggregate-reports GET /domains/{id}/setup GET /partner/organizations/{id}
OPERATIONAL OUTCOME

DMARC becomes another product in your shop. No support tickets to handle activation. No reconciliation work for billing. Customers stay inside your brand from purchase through daily use.

Two paths to API access

Enterprise and MSP accounts get API keys directly from the dashboard. Wholesalers and Resellers go through our partner team.
Contact partner team
Enterprise & MSP accounts
Enterprise & MSP accounts

Generate your API key directly from the Settings page in your EasyDMARC dashboard. No sales conversation required.

Wholesale & Resellers
Wholesale & Resellers

Partner-tier API access is provisioned through our partner team. Contact us to discuss your distribution model.

Enterprise-grade by design.

API-specific signals for security and procurement review.

DATA SOVEREIGNTY
5-region data residency

Reports process in 5 AWS regions. The hostname in your DNS decides which region. No cross-region transfer.

US · N. Virginia EU · Ireland Australia/NZ · Sydney Canada · Montreal Asia · India
API ACCESS
Authentication & access controls

Bearer token per API key. Scoped permissions per partner and per environment. SAML 2.0 SSO at the platform with Okta, Microsoft Entra ID, and Google Workspace. Every API call is logged.

Bearer token Scoped permissions SAML 2.0 SSO Okta Microsoft Entra ID Google Workspace
RELIABILITY
Stable API contract

Versioned endpoints. 12-month deprecation policy on stable endpoints. No surprise breaking changes. 99.9% uptime SLA backed by redundant infrastructure.

v1.0 12-month deprecation 99.9% uptime SLA Public status page
DATA SOVEREIGNTY
SOC 2 Type II + SOC 3 certified

Annual SSAE 18 audit by an independent third-party firm. ISO 27001-aligned operations. GDPR and CCPA compliant with DPA available. Annual third-party penetration testing.

SOC 2 Type II SOC 3 SSAE 18 ISO 27001-aligned GDPR CCPA DPA available

Every endpoint documented. Always current.

Complete method references, parameter schemas, response examples, and error codes, updated as new endpoints ship.

How do I get an API key?

Enterprise and MSP accounts can generate API keys directly from the Settings page in the EasyDMARC dashboard. Wholesale and Reseller accounts get partner-tier API access provisioned through our partner team. Pass the key in every request using the Authorization: Bearer <token> header.

https://api.easydmarc.com, HTTPS only. The current version is v1.0, accessed at paths like /v1.0/dns/dmarc. HTTP requests are not supported.

Yes. Batch endpoints cover all 11 DNS record types (A, AAAA, MX, NS, PTR, TXT, CNAME, DMARC, DKIM, SPF, BIMI) and domain creation. Use batch endpoints to reduce API calls and optimize against rate limits when querying multiple domains.

Yes. The DNS API runs lookups for 11 record types: A, AAAA, MX, NS, PTR, TXT, CNAME, DMARC, DKIM, SPF, and BIMI. Every record type supports single and batch lookups, so you can query one domain or thousands in a single workflow. PTR lookups cover reverse DNS.

Yes. Call /v1.0/dns/dmarc to retrieve a domain's DMARC record, or use the batch endpoint to check DMARC records across your whole portfolio. SPF, DKIM, and BIMI record checks work the same way through their own endpoints.

Bearer token authentication per API key for all standard API calls. Pass the token in the Authorization header on every request.

MSPs manage all client domains under a single MSP account. The Public API gives full access to onboarding domains in bulk, running DNS lookups, and pulling DMARC reports across the entire client base. Partner API access for multi-tenant operations is available to MSPs by agreement with our partner team.

Yes. EasyDMARC receives and parses raw RUA XML for you. The Aggregate Reports API returns that data as structured JSON, so you never need to build your own DMARC XML parser or reader. Pull the JSON into a SIEM, a data warehouse, or an internal dashboard.

Yes. The Failure Reports API lets you retrieve individual failure reports, download the EML source, download specific attachments, or pull all attachments as a ZIP archive. Aggregated statistics across failure reports are also available.

Pull parsed aggregate (RUA) report data as JSON for SIEM ingestion, and retrieve failure (RUF) reports with EML attachments for SOC forensics. Both come through the same REST API with Bearer token authentication, JSON responses, and standard HTTP status codes.

Yes. API requests are rate limited per API key. Use batch endpoints when querying multiple domains to minimize request count. Exact rate limits are documented in the developer reference.

All responses are returned in JSON. Successful responses include a data object and a meta object. Error responses include descriptive messages and standard HTTP status codes.

An email authentication API lets you check and monitor SPF, DKIM, DMARC, and BIMI records and pull authentication reporting into your own systems programmatically. The EasyDMARC Public API covers the full stack across 74 endpoints: DNS record lookups, DMARC aggregate and failure report data, and domain management.

Yes. The public API documentation repository lives at github.com/easydmarc/public-api-docs.