reporting
Based on domain events that act as triggers for sending alerts, the highly customizable Alert Central feature on dmarcian’s DMARC Management Platform allows you to monitor your domains without having to login to your dmarcian account. Events could include new or changed DNS records (e.g. we see a new DMARC record) and fluctuation in volume across categories of traffic for your domains. You can choose from common communication channels for alerts—email, Slack, Teams or webhook. The alert will provide you with the details of the event and a link to your dmarcian Timeline for you to get even more information. How does Alert Central Work? Alert Central is based around the dmarcian Timeline. Like the Timeline, you choose which changes to track, and the alerts ensure that you’re aware of the changes in real time. When we notice a DNS change, a change event gets triggered. If a DNS record
Though Cisco email security appliances (ESA) can be configured to send DMARC aggregate (RUA) reports, they have a limited number of daily DMARC reports they provide. This limit can be easily reached by organizations sending large volumes of email, especially if multiple subdomains are seen in the From header of messages received. The number of subdomains seen is an issue because of a deficiency in how the Cisco IronPort system generates DMARC reports. Instead of creating a single XML report containing data for the top-level domain and any subdomains (e.g. example.com along with www.example.com, server.example.com, etc), each server instance generates a completely separate report for each—this causes the limit to be reached rapidly. Increasing the daily limit will ensure that you have the proper visibility and are helping other organizations with their DMARC projects. The daily DMARC report default setting is 1000, which can be increased only through the command-line