Skip to scanner
dmark.is

dmark.is · Icelandic email security

Scan the DNS records attackers use to borrow your brand.

Run a public DMARC and SPF diagnostic, see exactly why spoofed mail can pass, then request early access for beta automation, reporting, and a safe path to p=reject.

Public scanner is live

0 logins

The first risk picture needs only public DNS.

Beta automation

Early access

SPF flattening and reporting stay gated until live-provider proof is complete.

Operator-managed rollout

Kastro

Kastro verifies DNS changes before they go live.

DMARC target

p=reject

Progress through monitor, quarantine, reject without breaking legitimate mail.

02 — The threat

Anyone can send email as your domain. Until you tell receivers not to let them.

Email was built on trust, not identity. Without an enforced DMARC policy, a stranger can put your address in the From field and reach your customers. Flip the switch to see the difference.

Inbox — bjorn@northwind.is2 messages
N
Northwind Billing ✓ DKIM PASS

billing@northwind.is

Your March statement is ready

Hi Björn — your monthly statement is attached…

N
Northwind Billing ✕ SPF FAIL · UNALIGNED

billing@northwind.is · sent via 185.220.101.4

URGENT: Update your payment details now

Your account is on hold. Confirm your card to avoid suspension…

p=none — both messages are delivered. The fake one looks identical.

1

An attacker sends mail “from” your domain

No password needed. SMTP lets anyone write your address in the From field.

2

Your domain has p=none or none at all

Receivers have no instruction to reject unaligned mail, so it sails through.

3

It lands in the inbox, looking legitimate

Your logo, your name, your customer — a convincing invoice or password reset.

DMARK closes the gap. We get you to an enforced p=reject safely — without breaking the legitimate mail your business depends on.

03 — The path

From a public scan to an enforced policy — without breaking mail.

DMARK is built for the messy middle: legacy vendors, SPF lookup limits, report XML nobody reads, and DNS providers where one bad edit takes mail down.

01

Discover

Find SPF, DMARC, DKIM, forwarding, and unknown senders — without asking anyone for credentials.

No login

02

Stabilize

Flatten SPF, remove stale includes, and document every DNS change before it ships.

Reversible

03

Enforce

Advance DMARC from none to quarantine to reject with report-backed confidence.

p=reject

The enforcement ladder

Most domains never leave the first rung.
01

p=none — watch only

02

p=quarantine — suspicious mail diverted

03

p=reject — spoofed mail blocked

04 — Premium tier

Move from exposed DNS records to enforced domain trust.

The paid product is in early access: scanner evidence is public today, while SPF automation and reporting remain gated until their launch checks are boring.

SPF flattening in beta

Keep Microsoft 365, Google Workspace, marketing tools, and local senders below the 10-lookup limit once the route is provisioned.

Readable reporting roadmap

Turn XML into sender inventory, pass/fail trends, and the next safe enforcement decision as reporting gates finish.

Provider-aware rollout

Copy-paste changes tailored for Icelandic DNS providers and reviewed for operational risk.

05 — Operational proof

Every recommendation should explain itself.

The product view translates DMARC aggregate reports, SPF chains, and DNS records into the next action a business can safely approve.

dmark audit console

northwind.is

F

p=none, 13 SPF lookups, 4 unknown senders

Flatten SPF includes

Remove stale HubSpot include

Ready

Quarantine rollout

Start at pct=25 for seven days

Review

Unknown sender

ASN 1299 fails alignment

Block

06 — Pricing

Start with proof. Pay when remediation is worth it.

The scanner stays public. The paid tiers are for teams who want automation, reporting, and safe implementation help.

Skoðun

Public diagnostic for teams that need a fast read on DMARC and SPF exposure.

0 ISK

  • Ungated domain scanner
  • Basic SPF and DMARC status
  • One-time technical breakdown

Sjálfvirkni

Early access while DNS publication and reporting gates finish.

Core

4,900 ISK/mo

  • SPF flattening beta
  • Readable reporting roadmap
  • Guided p=reject progression

Kastro Managed

Done-for-you implementation for directors who want DNS changes handled safely.

45,000 ISK setup + MRR

  • Implementation plan
  • DNS provider coordination
  • Post-change verification

Ready when you are

Show the spoofing gap before an attacker does.