Connect dmarcian
dmarcian is a DMARC management platform. It collects the aggregate and forensic reports that mail receivers send about your domains, classifies every source that sends mail as you, and tracks each…
Written By Christopher Scaminaci
Last updated About 2 hours ago
dmarcian is a DMARC management platform. It collects the aggregate and forensic reports that mail receivers send about your domains, classifies every source that sends mail as you, and tracks each domain's SPF, DKIM, DMARC, BIMI and TLS reporting posture. It raises issues (problems it found) and tasks (the next step toward enforcement) per domain, which is how an MSP moves client domains from monitoring to enforcement. StackJack talks to dmarcian through its REST API.
Connecting dmarcian to StackJack gives your AI assistant a family of dmarcian_ MCP tools. MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:
- See what needs attention: open issues and tasks across your domains, filtered by group, domain, state or date, and mute one that you have decided to accept
- Work your domain catalog: domains with the state of their SPF, DKIM and DMARC records, volumes and compliance; domain groups; adding, moving and removing domains; notes; refreshing and verifying a domain
- Watch for change: alert configurations and the alert events they raise, and the timeline of DNS record changes for your domains
- Plan enforcement: the policy planner's readiness view of which domains may be ready for a stricter, or a more relaxed, DMARC policy
- Dig into the data: Detail Viewer reports on aggregate data, the sources that send mail as your domains, TLS reporting failures and policies, and forensic reports (failure reports with real message content)
- Check any domain: inspect and validate DMARC, SPF, DKIM, BIMI and MTA-STS and TLS-RPT records, for a domain in your account or any other
- Manage users and access: the users on the account, who can read or write each domain group, and the account's other settings that dmarcian's API exposes
How StackJack authenticates to dmarcian
dmarcian uses an API token that belongs to a dmarcian user. StackJack sends it on every request. There is no client ID, no sign-in and no refresh: the token alone authenticates. Two things decide whether it works and what it can do:
- Your plan. dmarcian API access needs an Enterprise plan, or a partner arrangement that includes it.
- The user the token belongs to. A dmarcian token has no scopes: it acts as its user. The user's access decides what StackJack can do. The users and domain group access tools need an admin user, and a change to a domain group needs write access to it. A user with read access alone is a valid look-but-never-change connection.
Create a dedicated dmarcian user for StackJack and generate the token on that user. dmarcian says that generating a new token revokes the old one, so a token generated on your own user would stop any script of yours that already runs on it.
Pick your region
dmarcian runs six instances: us (Americas), eu (Europe, Middle East and Africa), au (Australia), ap (APAC), ca (Canada) and jp (Japan). Your account lives on one of them. dmarcian does not document that a token works on a different instance, so choose the instance you sign in on. StackJack uses that instance's API address and fills it in for you. There is no default region, because a token sent to the wrong instance fails in a way that looks exactly like a bad token.
StackJack has not checked the link between your sign-in address and the region against a live dmarcian account. If Test Connection answers an authentication error on a token you just made, try the other regions.
Steps
- Make a dedicated user and check your plan. Create a dmarcian user for StackJack. Give it admin access if you want StackJack to manage users and domain group access, write access to the domain groups you want StackJack to change, and read access alone for a connection that can look but never change anything.
- Generate the API token. Sign in to dmarcian as that user, open the Manage Settings page and generate an API token. Copy it, because StackJack cannot read it back.
- Find your region. Note which of the six instances you sign in on.
- Enter it in StackJack. Open Connectors, choose dmarcian, pick your Region, paste the token and save.
- Test the connection. StackJack reads your domain groups (every account has a default group), so the test proves the token, the region and the plan without changing anything.
The token is stored encrypted and is not shown again. Enter it again whenever you edit this connector. Changing only the region asks for the token again, which is deliberate: a save can never quietly replace a working token with a blank one.
What to know before your AI uses this connector
One connection per dmarcian account
dmarcian's API has no way to choose an account: every list is scoped to the account the token belongs to, or to what its user can see. If your clients are separate dmarcian accounts, add one named StackJack connection per account, each with a token from a user in that account. If your clients are domain groups inside one account, a single connection reaches them all, and the tools take a group id. The domain group list shows the ids.
Detail Viewer reports build in the background
A Detail Viewer report is created first, takes a little while to build, and is then read. The create tool answers at once with a search token. The progress tool reports how far along the report is, and the report data tools answer "not found" until it reaches 100. A report stays available for up to three days, and an expired one answers the same way, so create it again. The search token is a bearer token: anyone who holds it can read that report, so StackJack never records it.
Some tools change what dmarcian monitors or who can see it
Every change is a Pro tool, and the ones that matter most are labeled as changes that need approval. An AI assistant that honors that label shows you the action and waits for you to confirm. The confirmation is the assistant's, not StackJack's. A StackJack automation cannot run one of these at all until somebody signs off that it may take consequential actions on its own.
Those tools fall into groups:
- Deletes. Deleting a domain removes it and all its related data. Deleting a domain group removes the group and its settings (its domains are not deleted). Deleting an alert, a user or forensic data cannot be undone.
- Replacing a record. dmarcian offers a full-replace update next to most partial updates. The full replace can drop a field you leave out, so the partial update is the safer tool, and the descriptions say so.
- Access and people. Granting a user access to a domain group, revoking it, creating a user, changing a user's admin, forensic or billing access, converting a user to single sign-on, and sending an activation or password reset email all change who can see your data or reach a real person.
- Adding domains. Adding domains can raise your dmarcian bill, because dmarcian plans meter active domains and message volume.
- Routes dmarcian does not describe. Starting the My Network job and the staff notification statistics route are labeled as changes that need approval because dmarcian does not say what they do, and they may send an email or a notification.
Some answers contain secrets or personal data
dmarcian's user object carries each user's API token, so every tool in the users family is treated as sensitive: its answers are never recorded or saved as a file, and this connector never repeats a token value. A password change takes the old and the new password, so those arguments are kept out of StackJack's records too. Forensic reports contain content from real email, and they are not saved as a file either.
Domain verification has a cooldown
Verifying a domain starts a probe. dmarcian answers "too many requests" when it is asked too often for the same domain. That is a cooldown, not a problem with your token: wait a while and try again.
Lists come in pages
List tools take a page size up to 100 (the default is 10) and a page number starting at 1. Ask for a page at a time, and use the filters to narrow a large list.
Some routes are not part of dmarcian's published API
dmarcian's own generated API description carries a handful of routes that its published reference leaves out: staff administration, partner quotes, My Network (a dmarcian product for ESP and ISP partners), in-app notifications, a DKIM signing activity list, a newsletter sign-up, a few TLS reporting and BIMI helpers, and the route that serves the API description itself. They are included because they are part of that description. The staff routes are expected to refuse an ordinary customer's token, and their tool descriptions say so.
Plans
Reading is free. Every change needs the Pro plan on this connector.
Tool reference
See the generated dmarcian tool reference for the current inventory, plan assignment, input schemas and destructive-action labels.
dmarcian publishes no rate limit for its API, so StackJack paces requests on its own. Pacing smooths a burst. It does not guarantee that every call arrives, so check whether a change landed before repeating it. See Retrying a failed or timed-out write.
Troubleshooting
"dmarcian rejected the API token" (401). The token is wrong, was regenerated, or its user was removed. Generating a new token revokes the user's old one, so a 401 on a connection that used to work usually means somebody regenerated the token. Make a token on the dedicated StackJack user and paste it in. If the token is new, check the region.
"The dmarcian subscription on this account has expired" (402). The token is fine: the dmarcian account needs its subscription renewed before the API works again. Renew it, then run Test Connection.
"dmarcian accepted the token but not for this action" (403). The user the token belongs to is not permitted to perform that operation. The users and domain group access tools need an admin user, and a change to a domain group needs write access to it. API access is also an Enterprise plan feature, and dmarcian does not document what a plan without it answers, so a 403 on every call can mean the plan.
"That Detail Viewer report is not ready, or it has expired" (404). Create the report, check its progress until it reaches 100, then read the data. A report expires after three days.
"dmarcian is limiting how often this domain can be verified" (406). Wait and try again.
"Something answered at that address, but it was not the dmarcian API." A proxy, a firewall or a sign-in page replied instead of dmarcian. Check that nothing between StackJack and your dmarcian instance is rewriting the answer, and that the region is the instance your account lives on.
The connector worked and then stopped, with no change on your side. Check whether somebody regenerated the token on that user, then check that the dmarcian subscription is current.
dmarcian tools
dmarcian_ · 124 tools · Free 69 · Pro 55
DKIM Selectors
Domain Group Access
Domain Groups
Domains
Issues
Tasks
Alert Configurations
Alert Events
Policy Planner
TLS Reporting
Timeline
Detail Viewer
Forensic Viewer
Record Inspectors
Report Data
Source Viewer
API Description
My Network
Newsletter
Partner Quotes
Staff Admin Routes
User Notifications
Users
Was this helpful?
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team