Questions

Questions about OuterMark, answered.

Plain answers about the free check, the score, DMARC, prices, the portal, the partner programme and what OuterMark is not.

The free check

Do I need permission to check a domain?

The check reads only what any visitor or mail server can already see, so it works on any domain. The Full Report is for domains you own or look after.

What do you do with my email address?

We use it to send your report and to set up your free dashboard. We do not add you to a mailing list. You can ask us to delete your data at any time. See the privacy notice.

Why did my score change between two checks?

Usually because something changed: a certificate renewed, a record was edited. Sometimes a lookup did not finish the first time. The completeness line tells you which.

Why is my score lower than another tool's?

Most tools grade email alone. OuterMark also grades the website, the domain's registration and what is exposed to the internet, and it caps the score of any domain that can still be impersonated.

Can I check a domain that has no website?

Yes. The domain's website checks read "not applicable" and the rest are scored as usual.

The score

What do the words mean?

The score is out of 100. Excellent is 90 to 100, Good 75 to 89, Fair 60 to 74, Weak 40 to 59 and Poor 0 to 39. A scan missing a quarter or more of its checks is marked Incomplete, not given a word.

Why can a domain with perfect web security still score 69?

Because a domain anyone can impersonate is capped. Until DMARC is enforcing, the score can reach 69 at most, and at quarantine 89 at most. Only reject lifts the cap, however good the rest is.

Why does my score say Incomplete?

Some of its checks could not finish, and the line beside the score says how many did. A check that cannot finish, such as a lookup that times out, is recorded as unknown and never as a pass. A scan missing a quarter or more of its checks is marked Incomplete and given no word.

Can a partial scan score higher than a complete one?

Yes. A check that could not finish carries no penalty, which is why the completeness line is always shown.

DMARC

Will DMARC break our email?

Only if it is rushed. Real email breaks when a policy tightens before every real sender has been found and fixed. Done in steps, with evidence at each one, real email keeps arriving.

Does DMARC stop phishing?

It stops other people faking your domain. It does not stop phishing sent from other people's domains reaching you. That is a job for your email filter.

This domain never sends email. Does it need DMARC?

Yes. A domain that never sends is the easiest one to fake, because nobody is watching it. It can go straight to reject, since there is no real email to break.

We have SPF. Are we covered?

No. SPF checks the hidden return address, not the From line your customers read, and it breaks when a message is forwarded. DMARC, once enforced, is what protects the address people see, and it needs SPF or DKIM to pass for that same domain.

How long does it take?

With Managed DMARC, quarantine starts after about a month and reject comes after about four months. Each step waits for at least 30 days of evidence and for a person to approve it, so real email keeps arriving.

What is the 2026 standard?

DMARC was rewritten in May 2026 as RFC 9989, with RFC 9990 and RFC 9991 for its reports. It drops the percentage tag, adds a test mode and a policy for subdomains that do not exist, and expects reject to rest on DKIM.

Prices and paying

What happens if I cancel a DMARC plan?

Your DMARC record keeps working. If we host it, we hand it back 90 days later, with the exact text to publish in its place. Nobody is left without DMARC.

Is the Full Report per domain?

Yes. £50 buys the Full Report for one domain, and it is yours to keep.

Why does reject take four months?

Each step waits for at least 30 days of evidence that your real email is passing. We could set reject tomorrow. We will not, because that is how invoices go missing.

How do I pay?

By Direct Debit, set up when you sign up. Annual billing gives two months free.

What is the 90-day guarantee?

It comes with Managed DMARC and Scale. If we have not got your domain enforcing DMARC (p=quarantine) within 90 days of onboarding, for reasons within our control, your subscription is free from day 91 until we have. Quarantine starts after about a month. Reject takes about four months, on purpose, so real email keeps arriving.

What happens after a failed payment?

Nothing stops at once. After a failed payment your access carries on for 14 days, which gives you time to put the Direct Debit right.

The portal

How do I sign in?

With a link we email you, or the six-digit code in the same email, a Microsoft work account or a passkey. There is no password to remember. You stay signed in for up to 30 days, or until 14 days pass without a visit.

Is there an app?

The portal runs in any browser, phones included, and installs from the browser as an app on Chrome, Edge and an iPhone's home screen. It is not in an app store.

Can I delete my account?

Yes. The account holder can delete the account from the portal. It first lists what will go and the records to change in your own DNS, and it refuses while a domain still takes its DMARC policy from us, so nobody is left without DMARC.

Who can see my data?

The people on your account, and our engineers, who build and run OuterMark. If an IT provider manages your domains through OuterMark, its team can see them too. One partner never sees another partner's clients.

Partners

Does importing customers email them?

No, never. Neither does adding a customer through the API. And importing runs no scans.

Can our clients sign in to their own portal?

Yes, once a partner admin gives them a login from the Customers page. We show a one-time sign-in link for you to pass on. We email nobody.

Who answers our clients' support requests?

Your own desk, once you name it on the Brand page. Until you do, requests reach our support team.

Who can change a DMARC policy?

One of our engineers, by approving a step. A rule-based reviewer looks at each step first. Nothing in the API can change a policy.

How is one partner's data kept from another's?

Every read is scoped to the partner. A record that is not yours answers exactly as one that does not exist.

Is onboarding really one step?

For DMARC, SPF, MTA-STS and TLS reporting on Cloudflare DNS: one bulk request and one run of the records script. DKIM signing needs a script run twice in each Microsoft 365 tenant, with delegated admin access, or steps by hand in Google Workspace; BIMI needs each client's logo and a mark certificate. The Microsoft 365 script is proven on our own tenant and has not yet been run through a partner's access to a client's tenant.

Are you ready for the 2026 DMARC standard?

Yes. We read test mode the way the new standard applies it, and reject waits until every real sender signs with DKIM.

What OuterMark is not

Is it an inbox filter?

No. OuterMark does not filter anyone's inbox. Its email protection works through your DMARC policy, which, once enforced, tells receiving servers to junk or refuse email that fakes your domain. Phishing sent from other people's domains is a job for your email filter.

Is it a penetration test?

No. The scan is passive. It reads DNS records, fetches your website's front page as any visitor would, completes TLS handshakes with your web and mail servers, and reads public indexes. It does not try passwords, probe ports or attempt a way in. Anything intrusive needs your written permission and is a separate piece of work.

Is it an email provider?

No. Your email stays where it is. OuterMark works beside Microsoft 365, Google Workspace and whatever else sends your email.