Features Pricing
Free Tools
DMARC Checker SPF Checker DKIM Checker Domain Scanner Blacklist Checker Header Analyzer All 11 tools →
Resources
What is DMARC? What is SPF? What is DKIM? What is BIMI? Academy Blog Docs MSP Program Contact
Sign in Start →

Source Classification

Source Classification automatically categorises the email sending sources detected in your DMARC aggregate reports. Instead of manually reviewing each IP address and organisation to work out what service it belongs to, SpoofWard labels sources for you, saving time during source discovery and DMARC enforcement.

How it decides. This is a transparent scoring rule, not a machine-learning model. SpoofWard adds seven fixed weights — DMARC compliance (30), known-provider IP match (20), volume consistency (15), reverse-DNS/PTR (10), how long the source has been seen (10), SPF alignment (8) and DKIM alignment (7) — and places the total into a trust band. Nothing is trained on your data and the weights do not change over time. Every classification shows the reasons behind it, and you can override any of them.

Availability

AI Source Classification is available on Pro, Business, and Enterprise plans. The classification runs automatically in the background whenever new DMARC data is received — no manual configuration is needed.

How It Works

When SpoofWard processes your DMARC aggregate reports, each sending source is scored against several signals:

  • IP address and range — Matches IP addresses against known infrastructure of major email service providers, marketing platforms, and transactional senders
  • Reverse DNS (PTR) records — Analyzes the hostname associated with the sending IP for service identification clues
  • Organization name from WHOIS — Uses the registered organization to identify the entity operating the IP
  • Sending patterns — Examines volume, frequency, and authentication pass/fail ratios to infer the type of traffic
  • Historical classification data — Leverages classifications from other SpoofWard users (anonymized) to improve accuracy for well-known services

Classification Categories

Each detected source is assigned to one of the following categories:

  • Marketing — Email marketing platforms and bulk senders such as Mailchimp, HubSpot, SendGrid (marketing), Campaign Monitor, and similar services used for newsletters and promotional campaigns
  • Transactional — Services that send automated, one-to-one emails such as order confirmations, password resets, invoices, and notifications. Common examples include SendGrid (transactional), Amazon SES, Postmark, and Mandrill
  • Internal — Your organization's own mail servers, including on-premises Exchange or Google Workspace / Microsoft 365 infrastructure sending directly
  • Unknown — The source could not be confidently classified. This may indicate a lesser-known service, a self-hosted mail server, or insufficient data to make a determination
  • Suspicious — The source exhibits characteristics commonly associated with unauthorized sending or spoofing, such as failing authentication consistently, originating from residential IP ranges, or using infrastructure not associated with any known email service

Viewing Classifications

Source classifications appear throughout SpoofWard wherever sending sources are displayed:

  • Email Source Discovery — The Source Discovery page shows each source with its AI-assigned category badge, making it easy to sort and filter by type
  • Aggregate Reports — When drilling into Aggregate Report data, each sending source row includes its classification
  • DMARC Dashboard — The DMARC Dashboard uses classifications to group traffic by source type, giving you a high-level view of your email ecosystem

Overriding Classifications

If the AI assigns an incorrect category to a source, you can override the classification manually. Click on any source to open its detail panel, then select the correct category from the dropdown. Manual overrides take precedence over AI classifications and persist across future report processing.

Tip

When you override a classification, SpoofWard uses your correction to improve future accuracy. Over time, the AI learns from your overrides and applies them to similar sources automatically.

Using Classifications for DMARC Enforcement

AI Source Classification directly supports your path to DMARC enforcement. By categorizing sources automatically, you can:

  • Prioritize authorization — Focus on configuring SPF and DKIM for Marketing and Transactional sources first, as these represent legitimate email that should not be disrupted
  • Investigate unknowns — Sources classified as Unknown need manual review to determine if they are authorized senders that should be added to your SPF record
  • Act on suspicious sources — Sources flagged as Suspicious should be investigated immediately. If confirmed as unauthorized, you can block them via Allow/Block Rules and tighten your DMARC policy
  • Track progress — Monitor how many sources in each category have been authorized. When all Marketing, Transactional, and Internal sources pass authentication, you are ready to move to p=reject
Review Before Enforcement

Always review AI classifications before using them as the basis for policy changes. While the AI is accurate for well-known services, niche or self-hosted senders may be misclassified. Verify each source's identity before tightening your DMARC policy.

Your domain is being tested right now.
Are you watching?

Protect your brand and improve deliverability — automatically, with continuous monitoring and alerts.