Solution · DMARC Manager

Hosted DMARC and SPF.Enter once.Never change again.

Your domain points once to a zone maintained by Conbool. Policy, permitted senders and report address are managed there from then on.

Why DNS records for email go stale

SPF and DMARC change with every new sending service. DNS is often owned by another team or a service provider.

Every change is a ticket

New senders, a stricter policy, a different report address: every adjustment requires a DNS change.

SPF hits the lookup limit

SPF permits ten DNS lookups. With several sending services the limit is quickly exceeded, and the check fails.

Records disappear unnoticed

A provider change or a zone clean-up removes a record. It is noticed only when delivery suffers.

Many domains, inconsistent state

Every domain carries a different version. An overview of target and actual state is missing.

How delegation works

Two records, set once.

1. DMARC via CNAME

The _dmarc record of your domain points as a CNAME to the zone maintained by Conbool. The policy is managed there.

2. SPF via include

Your SPF record receives an include for Conbool. The permitted senders are collected behind this single reference.

3. Conbool maintains, you keep the zone

The zone stays with you. The delegation can be replaced by your own records at any time.

What DMARC Manager takes over permanently

Available as an add-on to every suite, billed per domain.

Policy without DNS changes

Every level from p=none to p=reject is set at the delegation target.

Senders in one place

Permitted sending sources are managed together. Your SPF record uses a single lookup for them.

Report address stays correct

The tenant report address is part of the maintained record. The analysis never runs empty.

Daily reconciliation

Records that were set are rechecked in DNS every day. A deviation is shown at the domain and in the audit log.

Setup at the provider

If the DNS provider supports Domain Connect, the records are set there after one confirmation.

Traceable changes

Every policy level is recorded with time and reason in the history of the domain.

Delegation and maintenance by hand

What changes with delegation.

 
Conbool DMARC Manager
Maintenance by hand
Changes in DNS
Two records, once
With every adjustment
SPF lookup limit
Senders collected behind one include
Grows with every sending service
Stricter policy
Set at the delegation target
DNS change per level
Lost records
Daily reconciliation, deviation visible
Noticed when delivery suffers
Control of the zone
Stays with the customer, delegation removable at any time
Stays with the customer
Many domains
Consistent state, one overview
A separate state per domain

As of October 2026. The right-hand column describes the usual approach without Conbool, not a specific vendor.

Hosted DMARC and SPF FAQ

What does hosted DMARC mean?
The DMARC record of your domain points via CNAME to a record that Conbool maintains. Changes to the policy are made there, not in your zone.
Why an include for SPF instead of a CNAME?
SPF sits at the name of the domain itself, where MX records also live. A CNAME is not permitted there. The include achieves the same.
Does Conbool control our DNS with this?
No. You set two records and can remove them at any time. Conbool has no access to your zone.
Does this work with every DNS provider?
Yes. CNAME and include are standard. Setup by confirmation at the provider requires Domain Connect and is therefore available only with supported providers.
What does the daily reconciliation check?
Whether the records that were set still exist in DNS and match the target. A deviation is shown at the domain and in the audit log.
How is it licensed?
DMARC Manager is available as an add-on to every suite. It is billed per domain, not per mailbox.

Delegate once, correct permanently.

DMARC Manager is available as an add-on to every suite and is billed per domain.