From the DMARC reports that receiving providers send back about mail claiming to be from your domain. It is first-party data about your own identity, not a purchased threat feed.
Threat Intelligence
Every failed authentication attempt is a data point about someone trying to use your identity. Most organisations throw that data away.
Once DMARC is enforced, the failures do not stop — they just stop being delivered. That stream is a live feed of who is attempting to impersonate your organisation, how often, and from which infrastructure. Treated as noise, it tells you nothing.
The other half of the problem is the vendors sending on your behalf. A marketing platform or invoicing service with weak authentication becomes the softest route to your customers, and their configuration is not something you control or routinely see.
Failure data is grouped into patterns rather than listed as events: a campaign spoofing your finance subdomain from one hosting provider looks different from background noise, and it is presented differently.
Every third party sending for you is tracked with its own alignment posture, so a vendor whose DKIM signing quietly broke becomes visible before it turns into failed customer mail or an open door.
Attack visibility
Risk posture
Week over week
It is worth being precise about the boundary here.
This tells you about abuse of your own domain. It is authoritative on that, because it is built from reports sent by the receiving mail providers themselves rather than inferred from external scanning.
It does not tell you about lookalike domains, which are registered elsewhere and never touch your DNS. Those need domain monitoring, which is a different control — and any vendor implying otherwise is overselling what DMARC data can see.
Used properly, it answers questions a security team is regularly asked and rarely able to evidence: are we being targeted, is it getting worse, and did our enforcement actually stop it.
Something not covered here? Talk to our team.
From the DMARC reports that receiving providers send back about mail claiming to be from your domain. It is first-party data about your own identity, not a purchased threat feed.
Not through DMARC data, and we would rather say so plainly. A lookalike is a separate registration that never interacts with your DNS, so it produces no reports. Detecting it requires domain monitoring as a distinct capability.
If your policy is at reject, the mail is already being blocked and the value is evidential — knowing you are targeted, and being able to show it. Beyond that, the infrastructure details support takedown requests and abuse reports.
No. A gateway inspects mail arriving at your organisation. This covers mail sent using your domain to anyone in the world, most of which never comes near your gateway. They address opposite directions.