๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

DMARC monitoring & auto-config

DMARC that configures itself, and won’t break your mail.

Lavawall® is a managed aggregate (rua) report receiver and an automatic per-domain configuration system. It reads your live DNS, writes the exact _dmarc record without clobbering third-party report addresses, and graduates you from p=none to reject with safe percentage stepping.

Start my free trial, no credit cardFix deliverability

Managed rua receiver · non-destructive record merge · multi-tenant for MSPs

Watch DMARC auto-configVideo coming soon

From reports to enforcement, safely

Managed rua report receiver

Point your aggregate reports at Lavawall® and it parses the XML for you, per-source pass/fail, live SPF and DMARC lookups, and a per-domain pass-rate you can actually read.

Non-destructive record writing

It generates the exact _dmarc TXT record and merges with existing third-party report addresses instead of overwriting them, hostname and value ready to copy to the clipboard.

One-click graduation

Move a domain from none to quarantine to reject with safe percentage stepping, and let live-DNS drift detection warn you the moment a record changes.

Analyst workflow & auto-discovery

Classify each source (authorized, phishing, suspicious, ignore) with a full audit trail, and let Lavawall® discover your sending domains from Microsoft 365, Google Workspace, and Scout.

the DMARC dashboard with per-source pass-rates

Why DMARC stopped being optional

In February 2024, Google and Yahoo began blocking mail from any organization that sends over 5,000 messages a day without DMARC configured. “It used to work” is no longer enough. DMARC builds on SPF and DKIM and tells receiving servers exactly what to do when a message fails those checks.

A DMARC policy has three enforcement states, published in your DNS:

  • p=none — deliver, just report. Monitoring only; nothing is blocked.
  • p=quarantine — send failing mail to the spam folder.
  • p=reject — refuse failing mail outright at the receiving server.

Lavawall® graduates you gradually with the pct= tag instead of flipping a switch: it steps quarantine in at pct=10, moves reject in at pct=25, and climbs toward pct=100 only once your aggregate (rua) reports show nothing but authorized senders in the failing column.

the automatic per-domain configuration card, showing live policy, the percentage slider, and the exact _dmarc TXT record ready to copy

See who is spoofing your domain

Every aggregate report names the sources sending as you: the reverse-DNS (rDNS) host name, the provider or ESP behind each one, the volume, and the SPF and DKIM pass-rate. Legitimate services you recognize can be authorized in a click; the attacker phishing your clients under your name is exactly what enforcement shuts down.

When a legitimate sender is the one failing alignment, Lavawall® hands you the exact records to fix it, so you reach reject without dropping your own invoices or newsletters.

a spoofing source called out with a plain-language reason and fix guidance for the affected domain

Fix each legitimate sender the right way

Most “failing” mail is not an attacker, it is a real service that was never set up correctly. Lavawall® pinpoints the misconfiguration and gives the exact DNS records to publish, for Mailchimp, SendGrid, Amazon SES, HubSpot and more, so the sender authenticates instead of getting filtered.

a DMARC alignment failure on a Mailchimp send, with the exact SPF and DKIM DNS records the sender should publish

Want DMARC taken to reject for you?

ThreeShield, the CISSP/CISA team behind Lavawall® will stage every domain from monitoring to enforcement without dropping a legitimate email, across all your tenants.

Common questions

Will this overwrite my existing DMARC record?
No, it reads live DNS and merges non-destructively, preserving existing third-party report addresses while adding its own rua receiver.
How do I move to enforcement safely?
One-click graduation from none to quarantine to reject with safe percentage stepping, plus live-DNS drift detection and a per-source analyst audit trail.
Does it find my sending domains?
Yes, auto-discovery from Microsoft 365, Google Workspace, and Scout, with per-domain SPF/DMARC pass-rates. Multi-tenant for MSPs.

Start my free trial →