DMARC monitoring & auto-config
DMARC that configures itself, and won’t break your mail.
Lavawall® is a managed aggregate (rua) report receiver and an automatic per-domain configuration system. It reads your live DNS, writes the exact _dmarc record without clobbering third-party report addresses, and graduates you from p=none to reject with safe percentage stepping.
Start my free trial, no credit cardFix deliverability
Managed rua receiver · non-destructive record merge · multi-tenant for MSPs
From reports to enforcement, safely
Managed rua report receiver
Point your aggregate reports at Lavawall® and it parses the XML for you, per-source pass/fail, live SPF and DMARC lookups, and a per-domain pass-rate you can actually read.
Non-destructive record writing
It generates the exact _dmarc TXT record and merges with existing third-party report addresses instead of overwriting them, hostname and value ready to copy to the clipboard.
One-click graduation
Move a domain from none to quarantine to reject with safe percentage stepping, and let live-DNS drift detection warn you the moment a record changes.
Analyst workflow & auto-discovery
Classify each source (authorized, phishing, suspicious, ignore) with a full audit trail, and let Lavawall® discover your sending domains from Microsoft 365, Google Workspace, and Scout.

Why DMARC stopped being optional
In February 2024, Google and Yahoo began blocking mail from any organization that sends over 5,000 messages a day without DMARC configured. “It used to work” is no longer enough. DMARC builds on SPF and DKIM and tells receiving servers exactly what to do when a message fails those checks.
A DMARC policy has three enforcement states, published in your DNS:
- p=none — deliver, just report. Monitoring only; nothing is blocked.
- p=quarantine — send failing mail to the spam folder.
- p=reject — refuse failing mail outright at the receiving server.
Lavawall® graduates you gradually with the pct= tag instead of flipping a switch: it steps quarantine in at pct=10, moves reject in at pct=25, and climbs toward pct=100 only once your aggregate (rua) reports show nothing but authorized senders in the failing column.

See who is spoofing your domain
Every aggregate report names the sources sending as you: the reverse-DNS (rDNS) host name, the provider or ESP behind each one, the volume, and the SPF and DKIM pass-rate. Legitimate services you recognize can be authorized in a click; the attacker phishing your clients under your name is exactly what enforcement shuts down.
When a legitimate sender is the one failing alignment, Lavawall® hands you the exact records to fix it, so you reach reject without dropping your own invoices or newsletters.

Fix each legitimate sender the right way
Most “failing” mail is not an attacker, it is a real service that was never set up correctly. Lavawall® pinpoints the misconfiguration and gives the exact DNS records to publish, for Mailchimp, SendGrid, Amazon SES, HubSpot and more, so the sender authenticates instead of getting filtered.

Want DMARC taken to reject for you?
ThreeShield, the CISSP/CISA team behind Lavawall® will stage every domain from monitoring to enforcement without dropping a legitimate email, across all your tenants.
Common questions
- Will this overwrite my existing DMARC record?
- No, it reads live DNS and merges non-destructively, preserving existing third-party report addresses while adding its own rua receiver.
- How do I move to enforcement safely?
- One-click graduation from none to quarantine to reject with safe percentage stepping, plus live-DNS drift detection and a per-source analyst audit trail.
- Does it find my sending domains?
- Yes, auto-discovery from Microsoft 365, Google Workspace, and Scout, with per-domain SPF/DMARC pass-rates. Multi-tenant for MSPs.