Skip to main content
Connector guides

Connect dmarcian

dmarcian is a DMARC management platform. It collects the aggregate and forensic reports that mail receivers send about your domains, classifies every source that sends mail as you, and tracks each…

Written By Christopher Scaminaci

Last updated About 3 hours ago

dmarcian is a DMARC management platform. It collects the aggregate and forensic reports that mail receivers send about your domains, classifies every source that sends mail as you, and tracks each domain's SPF, DKIM, DMARC, BIMI and TLS reporting posture. It raises issues (problems it found) and tasks (the next step toward enforcement) per domain, which is how an MSP moves client domains from monitoring to enforcement. StackJack talks to dmarcian through its REST API.

Connecting dmarcian to StackJack gives your AI assistant a family of dmarcian_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • See what needs attention: open issues and tasks across your domains, filtered by group, domain, state or date, and mute one that you have decided to accept
  • Work your domain catalog: domains with the state of their SPF, DKIM and DMARC records, volumes and compliance; domain groups; adding, moving and removing domains; notes; refreshing and verifying a domain
  • Watch for change: alert configurations and the alert events they raise, and the timeline of DNS record changes for your domains
  • Plan enforcement: the policy planner's readiness view of which domains may be ready for a stricter, or a more relaxed, DMARC policy
  • Dig into the data: Detail Viewer reports on aggregate data, the sources that send mail as your domains, TLS reporting failures and policies, and forensic reports (failure reports with real message content)
  • Check any domain: inspect and validate DMARC, SPF, DKIM, BIMI and MTA-STS and TLS-RPT records, for a domain in your account or any other
  • Manage users and access: the users on the account, who can read or write each domain group, and the account's other settings that dmarcian's API exposes

How StackJack authenticates to dmarcian

dmarcian uses an API token that belongs to a dmarcian user. StackJack sends it on every request. There is no client ID, no sign-in and no refresh: the token alone authenticates. Two things decide whether it works and what it can do:

  • Your plan. dmarcian API access needs an Enterprise plan, or a partner arrangement that includes it.
  • The user the token belongs to. A dmarcian token has no scopes: it acts as its user. The user's access decides what StackJack can do. The users and domain group access tools need an admin user, and a change to a domain group needs write access to it. A user with read access alone is a valid look-but-never-change connection.

Create a dedicated dmarcian user for StackJack and generate the token on that user. dmarcian says that generating a new token revokes the old one, so a token generated on your own user would stop any script of yours that already runs on it.

Pick your region

dmarcian runs six instances: us (Americas), eu (Europe, Middle East and Africa), au (Australia), ap (APAC), ca (Canada) and jp (Japan). Your account lives on one of them. dmarcian does not document that a token works on a different instance, so choose the instance you sign in on. StackJack uses that instance's API address and fills it in for you. There is no default region, because a token sent to the wrong instance fails in a way that looks exactly like a bad token.

StackJack has not checked the link between your sign-in address and the region against a live dmarcian account. If Test Connection answers an authentication error on a token you just made, try the other regions.

Steps

  1. Make a dedicated user and check your plan. Create a dmarcian user for StackJack. Give it admin access if you want StackJack to manage users and domain group access, write access to the domain groups you want StackJack to change, and read access alone for a connection that can look but never change anything.
  2. Generate the API token. Sign in to dmarcian as that user, open the Manage Settings page and generate an API token. Copy it, because StackJack cannot read it back.
  3. Find your region. Note which of the six instances you sign in on.
  4. Enter it in StackJack. Open Connectors, choose dmarcian, pick your Region, paste the token and save.
  5. Test the connection. StackJack reads your domain groups (every account has a default group), so the test proves the token, the region and the plan without changing anything.

The token is stored encrypted and is not shown again. Enter it again whenever you edit this connector. Changing only the region asks for the token again, which is deliberate: a save can never quietly replace a working token with a blank one.

What to know before your AI uses this connector

One connection per dmarcian account

dmarcian's API has no way to choose an account: every list is scoped to the account the token belongs to, or to what its user can see. If your clients are separate dmarcian accounts, add one named StackJack connection per account, each with a token from a user in that account. If your clients are domain groups inside one account, a single connection reaches them all, and the tools take a group id. The domain group list shows the ids.

Detail Viewer reports build in the background

A Detail Viewer report is created first, takes a little while to build, and is then read. The create tool answers at once with a search token. The progress tool reports how far along the report is, and the report data tools answer "not found" until it reaches 100. A report stays available for up to three days, and an expired one answers the same way, so create it again. The search token is a bearer token: anyone who holds it can read that report, so StackJack never records it.

Some tools change what dmarcian monitors or who can see it

Every change is a Pro tool, and the ones that matter most are labeled as changes that need approval. An AI assistant that honors that label shows you the action and waits for you to confirm. The confirmation is the assistant's, not StackJack's. A StackJack automation cannot run one of these at all until somebody signs off that it may take consequential actions on its own.

Those tools fall into groups:

  • Deletes. Deleting a domain removes it and all its related data. Deleting a domain group removes the group and its settings (its domains are not deleted). Deleting an alert, a user or forensic data cannot be undone.
  • Replacing a record. dmarcian offers a full-replace update next to most partial updates. The full replace can drop a field you leave out, so the partial update is the safer tool, and the descriptions say so.
  • Access and people. Granting a user access to a domain group, revoking it, creating a user, changing a user's admin, forensic or billing access, converting a user to single sign-on, and sending an activation or password reset email all change who can see your data or reach a real person.
  • Adding domains. Adding domains can raise your dmarcian bill, because dmarcian plans meter active domains and message volume.
  • Routes dmarcian does not describe. Starting the My Network job and the staff notification statistics route are labeled as changes that need approval because dmarcian does not say what they do, and they may send an email or a notification.

Some answers contain secrets or personal data

dmarcian's user object carries each user's API token, so every tool in the users family is treated as sensitive: its answers are never recorded or saved as a file, and this connector never repeats a token value. A password change takes the old and the new password, so those arguments are kept out of StackJack's records too. Forensic reports contain content from real email, and they are not saved as a file either.

Domain verification has a cooldown

Verifying a domain starts a probe. dmarcian answers "too many requests" when it is asked too often for the same domain. That is a cooldown, not a problem with your token: wait a while and try again.

Lists come in pages

List tools take a page size up to 100 (the default is 10) and a page number starting at 1. Ask for a page at a time, and use the filters to narrow a large list.

Some routes are not part of dmarcian's published API

dmarcian's own generated API description carries a handful of routes that its published reference leaves out: staff administration, partner quotes, My Network (a dmarcian product for ESP and ISP partners), in-app notifications, a DKIM signing activity list, a newsletter sign-up, a few TLS reporting and BIMI helpers, and the route that serves the API description itself. They are included because they are part of that description. The staff routes are expected to refuse an ordinary customer's token, and their tool descriptions say so.

Plans

Reading is free. Every change needs the Pro plan on this connector.

Tool reference

See the generated dmarcian tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.

dmarcian publishes no rate limit for its API, so StackJack paces requests on its own. Pacing smooths a burst. It does not guarantee that every call arrives, so check whether a change landed before repeating it. See Retrying a failed or timed-out write.

Troubleshooting

"dmarcian rejected the API token" (401). The token is wrong, was regenerated, or its user was removed. Generating a new token revokes the user's old one, so a 401 on a connection that used to work usually means somebody regenerated the token. Make a token on the dedicated StackJack user and paste it in. If the token is new, check the region.

"The dmarcian subscription on this account has expired" (402). The token is fine: the dmarcian account needs its subscription renewed before the API works again. Renew it, then run Test Connection.

"dmarcian accepted the token but not for this action" (403). The user the token belongs to is not permitted to perform that operation. The users and domain group access tools need an admin user, and a change to a domain group needs write access to it. API access is also an Enterprise plan feature, and dmarcian does not document what a plan without it answers, so a 403 on every call can mean the plan.

"That Detail Viewer report is not ready, or it has expired" (404). Create the report, check its progress until it reaches 100, then read the data. A report expires after three days.

"dmarcian is limiting how often this domain can be verified" (406). Wait and try again.

"Something answered at that address, but it was not the dmarcian API." A proxy, a firewall or a sign-in page replied instead of dmarcian. Check that nothing between StackJack and your dmarcian instance is rewriting the answer, and that the region is the instance your account lives on.

The connector worked and then stopped, with no change on your side. Check whether somebody regenerated the token on that user, then check that the dmarcian subscription is current.

dmarcian tools

dmarcian_ · 124 tools · Free 69 · Pro 55

DKIM Selectors

ToolWhat it does
dmarcian_get_dkim_selector
Free · Read-only
Gets one DKIM signing activity record by id.
dmarcian_list_dkim_selectors
Free · Read-only
Lists DKIM signing activity records.

Domain Group Access

ToolWhat it does
dmarcian_grant_group_read_access
Pro · Destructive
DESTRUCTIVE.
dmarcian_grant_group_write_access
Pro · Destructive
DESTRUCTIVE.
dmarcian_list_domain_group_access
Free · Read-only
Lists every domain group with each user's access level on it (read-write or read-only).
dmarcian_revoke_group_access
Pro · Destructive
DESTRUCTIVE.

Domain Groups

ToolWhat it does
dmarcian_add_domains_to_group
Pro · Destructive
DESTRUCTIVE.
dmarcian_create_domain_group
Pro · Write
Creates a domain group owned by the user.
dmarcian_delete_domain_group
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_domain_group
Free · Read-only
Gets one domain group by id.
dmarcian_list_domain_groups
Free · Read-only
Lists the account's domain groups.
dmarcian_move_domains_to_group
Pro · Write
Moves domains from their source group into the target group (the group in the path).
dmarcian_remove_domains_from_group
Pro · Write
Removes domains from the target group (the group in the path), except the DEFAULT group.
dmarcian_replace_domain_group
Pro · Destructive
DESTRUCTIVE.
dmarcian_update_domain_group
Pro · Write
Updates some of a domain group's settings (label, notes, parkedDomains, hideAssignedDomains); fields you leave out are not sent.

Domains

ToolWhat it does
dmarcian_delete_domain
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_domain
Free · Read-only
Gets one domain's details by id.
dmarcian_list_domains
Free · Read-only
Lists the domains the current user has access to, with the state of each domain's SPF, DKIM and DMARC records, its message volumes and its compliance level.
dmarcian_refresh_domain
Pro · Write
Refreshes the domain's statistics.
dmarcian_replace_domain
Pro · Destructive
DESTRUCTIVE.
dmarcian_update_domain
Pro · Write
Updates some of a domain's properties (notes, topLevel, spfLookupCount, lastUploadTime); fields you leave out are not sent.
dmarcian_verify_domain
Pro · Write
Starts a probe to verify the domain.

Issues

ToolWhat it does
dmarcian_get_issue
Free · Read-only
Gets one issue by id.
dmarcian_list_issues
Free · Read-only
Lists the domain issues dmarcian has discovered for the account: problems found while monitoring the domains, mainly in SPF, DKIM and DMARC records.
dmarcian_replace_issue
Pro · Write
Updates an issue's properties (full replace; prefer dmarcian_update_issue for a partial edit).
dmarcian_update_issue
Pro · Write
Updates some of an issue's properties.

Tasks

ToolWhat it does
dmarcian_get_task
Free · Read-only
Gets one task by id.
dmarcian_list_tasks
Free · Read-only
Lists the domain tasks dmarcian has generated for the account: the next steps in a journey to deploy DMARC.
dmarcian_replace_task
Pro · Write
Updates a task's properties (full replace; prefer dmarcian_update_task for a partial edit).
dmarcian_update_task
Pro · Write
Updates some of a task's properties.

Alert Configurations

ToolWhat it does
dmarcian_create_alert
Pro · Write
Creates a new alert configuration.
dmarcian_delete_alert
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_alert
Free · Read-only
Fetches one alert configuration by id.
dmarcian_list_alerts
Free · Read-only
Pages through the alert configurations: the rules that raise alert events for the account's domains.
dmarcian_update_alert
Pro · Destructive
DESTRUCTIVE.

Alert Events

ToolWhat it does
dmarcian_get_alert_event
Free · Read-only
Fetches one alert event by id.
dmarcian_list_alert_events
Free · Read-only
Pages through alert events.

Policy Planner

ToolWhat it does
dmarcian_create_policy_filter
Free · Read-only
Creates a policy planner filter limited to a set of domains, to pass to dmarcian_list_policy_domains as filterId.
dmarcian_get_policy_filter
Free · Read-only
Retrieves one policy planner filter's details.
dmarcian_list_policy_domains
Free · Read-only
Lists the policy domains the current user has access to: each domain's state of DMARC deployment and the readiness information that helps decide when a domain may be ready for a more aggressive, or more relaxed, DMARC policy.
dmarcian_list_policy_filters
Free · Read-only
Lists the latest policy planner filters created by the user.

TLS Reporting

ToolWhat it does
dmarcian_get_tls_policy_domain_detail
Pro · Write
Sends a TLS viewer filter (a date range, domains, policies, policy modes and failures only) and answers the policy domain detail for it.
dmarcian_get_tls_report
Free · Read-only
Retrieves one TLS policy detail by id.
dmarcian_get_tls_submission
Free · Read-only
Retrieves one TLS report submission by id.
dmarcian_list_tls_failures
Free · Read-only
Lists all TLS failure details per error type: visibility into connection issues between external servers sending messages to the domains.
dmarcian_list_tls_reports
Free · Read-only
Lists all TLS report policy data (the TLS policy list).
dmarcian_upload_tls_report
Pro · Write
Uploads a TLS report file (a multipart upload).

Timeline

ToolWhat it does
dmarcian_create_timeline_filter
Free · Read-only
Creates a timeline event filter: a set of criteria to pass to dmarcian_list_timeline_events as filterId.
dmarcian_get_timeline_filter
Free · Read-only
Retrieves one timeline event filter's details.
dmarcian_list_timeline_events
Free · Read-only
Lists timeline events: changes made to the DNS records associated with the domains.
dmarcian_list_timeline_filters
Free · Read-only
Lists the latest timeline event filters created by the user.

Detail Viewer

ToolWhat it does
dmarcian_create_report_job
Free · Read-only
Creates a Detail Viewer report job for a date range and filters.
dmarcian_get_report_job
Free · Read-only
Gets one Detail Viewer report job by its search token.
dmarcian_list_report_jobs
Free · Read-only
Lists the current user's Detail Viewer reports (the aggregate report explorer).

Forensic Viewer

ToolWhat it does
dmarcian_create_forensic_report_job
Free · Read-only
Creates a forensic report job with filter criteria; its search token is what dmarcian_list_forensic_data pages.
dmarcian_delete_all_forensic_data
Pro · Destructive
DESTRUCTIVE.
dmarcian_delete_forensic_records
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_forensic_report_job
Free · Read-only
Gets one forensic report job's details.
dmarcian_list_forensic_data
Free · Read-only
Returns a paginated list of forensic data records (failure reports generated by DMARC capable receivers for email that failed the DMARC check).
dmarcian_list_forensic_report_jobs
Free · Read-only
Lists the existing forensic report jobs.

Record Inspectors

ToolWhat it does
dmarcian_build_bimi_record
Pro · Write
Builds a BIMI record for a domain from an image URL and an optional VMC URL, or a BIMI decline.
dmarcian_inspect_bimi_record
Free · Read-only
Inspects a domain's BIMI record details, including the certificate and SVG information.
dmarcian_inspect_dkim_record
Free · Read-only
Inspects the published DKIM record for a domain and selector.
dmarcian_inspect_dmarc_record
Free · Read-only
Inspects the published DMARC record for a domain.
dmarcian_inspect_mta_sts_policy
Free · Read-only
Views the published MTA-STS policy file for a domain.
dmarcian_inspect_mta_sts_record
Free · Read-only
Views the MTA-STS records for a domain.
dmarcian_inspect_spf_record
Free · Read-only
Analyzes and validates a domain's SPF record.
dmarcian_inspect_tls_rpt_record
Free · Read-only
Analyzes and validates the TLS reporting (TLS-RPT) record for a domain.
dmarcian_validate_dkim_record
Free · Read-only
Validates a DKIM record string.
dmarcian_validate_dmarc_record
Free · Read-only
Validates a DMARC record string.
dmarcian_verify_bimi_svg
Pro · Write
Verifies a BIMI SVG, given as a URL or as the SVG content, and can minify it.

Report Data

ToolWhat it does
dmarcian_get_report_progress
Free · Read-only
Returns the current progress of report generation as a percentage value and a human-readable label.
dmarcian_get_report_sources
Free · Read-only
Lists the report's sources in four categories: DMARC capable, non compliant, forwarders and unknown.
dmarcian_list_report_domains
Free · Read-only
Lists the report's detailed data grouped by header-from domain.
dmarcian_list_report_source_data
Free · Read-only
Lists one source's data in the report, such as message counts and the SPF, DKIM and DMARC information.

Source Viewer

ToolWhat it does
dmarcian_create_source_filter
Free · Read-only
Creates a source filter limited to a set of domains, to pass to the source tools as filterId.
dmarcian_get_source_filter
Free · Read-only
Retrieves one source filter's details.
dmarcian_get_sources_refresh
Free · Read-only
Gets the source refresh record: when the cached Source Viewer data was last refreshed.
dmarcian_list_source_domains
Free · Read-only
Lists the account's known domain volume by source.
dmarcian_list_source_filters
Free · Read-only
Lists the stored source filters, newest first.
dmarcian_list_sources
Free · Read-only
Lists the account's known sources with volume totals.
dmarcian_refresh_sources
Pro · Write
Triggers a refresh of the cached Source Viewer data.

API Description

ToolWhat it does
dmarcian_get_schema
Free · Read-only
Gets the OpenAPI description of dmarcian's REST API from the vendor's schema route, as JSON (StackJack always asks for the JSON form).

My Network

ToolWhat it does
dmarcian_get_my_network_alert
Free · Read-only
Gets the My Network alert settings: the alert email address, the alert percentage and whether sending is enabled.
dmarcian_get_my_network_job
Free · Read-only
Gets the My Network job: its state, progress and created time.
dmarcian_set_my_network_alert
Pro · Write
Sets the My Network alert settings: the alert email address, the alert percentage (0 to 100) and whether sending is enabled.
dmarcian_start_my_network_job
Pro · Destructive
DESTRUCTIVE.

Newsletter

ToolWhat it does
dmarcian_subscribe_to_mailing_list
Pro · Destructive
DESTRUCTIVE.

Partner Quotes

ToolWhat it does
dmarcian_create_quote
Pro · Write
Creates a partner price quote for a user (created_for is the user's id).
dmarcian_delete_quote
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_quote
Free · Read-only
Gets one partner price quote by id.
dmarcian_list_quotes
Free · Read-only
Lists partner price quotes.
dmarcian_replace_quote
Pro · Destructive
DESTRUCTIVE.
dmarcian_update_quote
Pro · Write
Updates some of a partner price quote's fields; fields you leave out are not sent.

Staff Admin Routes

ToolWhat it does
dmarcian_admin_create_usage_export
Pro · Write
Creates an account usage export report job.
dmarcian_admin_create_user_notification
Pro · Destructive
DESTRUCTIVE.
dmarcian_admin_delete_user_notification
Pro · Destructive
DESTRUCTIVE.
dmarcian_admin_get_accounting_review_stats
Free · Read-only
Gets the accounting review statistics.
dmarcian_admin_get_notification_send_stats
Pro · Destructive
DESTRUCTIVE.
dmarcian_admin_get_usage_export
Free · Read-only
Gets one account usage export report job by id.
dmarcian_admin_get_user_notification
Free · Read-only
Gets one user notification by id.
dmarcian_admin_list_notification_levels
Free · Read-only
Lists the notification levels.
dmarcian_admin_list_notification_types
Free · Read-only
Lists the notification types.
dmarcian_admin_list_usage_exports
Free · Read-only
Lists the account usage export report jobs.
dmarcian_admin_list_user_notifications
Free · Read-only
Lists user notifications across users.
dmarcian_admin_notify_user
Pro · Destructive
DESTRUCTIVE.
dmarcian_admin_replace_user_notification
Pro · Destructive
DESTRUCTIVE.
dmarcian_admin_update_user_notification
Pro · Write
Updates some of a user notification's fields; fields you leave out are not sent.

User Notifications

ToolWhat it does
dmarcian_create_user_notification
Pro · Write
Creates a user notification record; the only writable field is dismissed.
dmarcian_delete_user_notification
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_user_notification
Free · Read-only
Gets one in-app notification by id.
dmarcian_list_user_notifications
Free · Read-only
Lists the current user's in-app notifications.
dmarcian_replace_user_notification
Pro · Write
Updates an in-app notification (full replace; prefer dmarcian_update_user_notification).
dmarcian_update_user_notification
Pro · Write
Updates an in-app notification.

Users

ToolWhat it does
dmarcian_change_user_password
Pro · Destructive
DESTRUCTIVE.
dmarcian_convert_user_to_sso
Pro · Destructive
DESTRUCTIVE.
dmarcian_create_user
Pro · Destructive
DESTRUCTIVE.
dmarcian_delete_user
Pro · Destructive
DESTRUCTIVE.
dmarcian_get_user
Free · Read-only
Gets one user's details by id.
dmarcian_list_users
Free · Read-only
Lists the users of the account.
dmarcian_replace_user
Pro · Destructive
DESTRUCTIVE.
dmarcian_reset_user_password
Pro · Destructive
DESTRUCTIVE.
dmarcian_send_user_activation_reminder
Pro · Destructive
DESTRUCTIVE.
dmarcian_update_user
Pro · Destructive
DESTRUCTIVE.