Privacy controls
CyberFurl can load analytics only after you opt in. Core product features work without analytics consent.
Perform deep technical threat intelligence gathering by querying the Open Threat Exchange (OTX). Correlate indicators of compromise (IoCs), parse structured STIX/TAXII pulses, and analyze real-time telemetry for IPv4/IPv6 addresses, domains, file hashes, and URIs.
DMARC (Domain-based Message Authentication, Reporting, and Conformance) is an email authentication protocol that builds on SPF and DKIM. It tells receiving mail servers how to handle emails that fail authentication checks, protecting your domain from spoofing and phishing attacks.
Without DMARC, anyone can send email using your domain. DMARC prevents phishing and improves your domain's sender reputation with mailbox providers.
Using "p=none" indefinitely, missing rua tags, and failing to align subdomains are the top causes of audit failure.
Type your root or subdomain into the lookup tool above.
Our scanners query global DNS records in real-time.
Analyze syntax, policy mode, and alignment parameters.
Follow our recommendations to reach p=reject status.
Reads the p= tag from your DMARC TXT record and evaluates whether your domain enforces none (monitor only), quarantine (route to spam), or reject (block outright). Reject is recommended for full protection.
Checks that your rua= (aggregate reports) and ruf= (forensic/failure reports) mailto addresses are published and reachable. Missing reporting tags means you get no visibility into who sends email as your domain.
Inspects the adkim= and aspf= tags to determine whether your domain requires strict or relaxed alignment between the RFC5321.MailFrom, the DKIM d= domain, and the visible From header.
Parses the full DMARC record for illegal characters, duplicate tags, incorrect quoting, and other formatting errors that can cause receiving servers to silently ignore the record.
Evaluates the sp= tag to determine how subdomains inherit or override the organizational domain policy. If sp= is missing, subdomains fall back to the parent p= tag which may leave them unprotected.
Combines policy strength, alignment mode, reporting coverage, and subdomain posture into a single letter grade (A+ through F) so you can quickly assess your domain's overall resistance to email spoofing.
Analyze IPs, domains, or hashes against the global Open Threat Exchange to uncover hidden campaigns and preemptively block malicious infrastructure.