Getting Started with SpoofWard
This guide will walk you through the essential first steps to get your domain protected with SpoofWard. You'll be monitoring email authentication within 15 minutes.
Step 1: Create Your Account
Visit SpoofWard.com and click "Get Started Free."
- Enter your email address
- Create a strong password
- Verify your email address (check your inbox for a verification link)
- You're all set! Your account is ready to use.
Use your organizational email (not personal email) so teammates you invite to your workspace recognise it.
Step 2: Your Workspace Is Created Automatically
When you register, SpoofWard automatically creates a workspace for you and makes you its owner — there is nothing to fill in. Your workspace is the container for all your domains, team members, and settings. You can rename it and invite teammates later under Settings → Team.
Right after registering you land in a short setup flow: add your first domain, verify it, and connect DMARC reporting.
Step 3: Add Your First Domain
Enter your domain name (e.g., example.com) in the setup flow, or click "Add Domain" from the Domains page later.
Important: You must be able to add DNS TXT records to verify domain ownership.
Domain Verification
SpoofWard provides a DNS verification string. To verify:
- Log in to your DNS provider (GoDaddy, Cloudflare, Route 53, etc.)
- Create a new TXT record in your domain's DNS
- Copy the verification string from SpoofWard
- Paste it as the record value
- Save the DNS record
- Return to SpoofWard and click "Verify Domain"
Verification usually completes within 5 minutes (sometimes up to 24 hours if DNS is slow to propagate).
Don't have direct DNS access? You can authorize team members or use SpoofWard's Hosted DNS service (Pro plan) to simplify management.
Step 4: Configure DMARC Reporting
DMARC reports are the foundation of SpoofWard's intelligence. You must point your DMARC reports to SpoofWard to receive monitoring data.
Set Your DMARC Record
In your DNS provider, create or update your DMARC record (usually at _dmarc.example.com):
v=DMARC1; p=none; rua=mailto:[email protected]
Key fields:
p=none- Start in monitoring mode (no enforcement yet)rua=mailto:[email protected]- Aggregate report address (required)
Forensic reports (ruf=) are optional and off by default: they can contain message content, so enable them only if you need them.
If you already have a DMARC record, add rua=mailto:[email protected] to it (comma-separated if you already have another rua address) instead of replacing the entire record. Preserve any existing policy and settings. The domain page's Connect reporting section generates this record for you.
Wait for Reports
DMARC reports are sent once daily by receiving mail servers. Allow 24–48 hours for the first reports to arrive. During this time the domain page shows First report received: Not yet — this is normal. The domain page reports five separate facts: whether the DMARC record published right now routes reports to SpoofWard, when the first report arrived, when the last one arrived, how many arrived in the selected period, and how they most likely reached us. None of these implies another — reports can also reach us by forwarding, manual import or an older record. Note that a verified domain is not yet protected: verification only proves ownership; reporting and an enforcement policy are separate steps shown on the domain page.
Step 5: Review Your Security Score
Once reports arrive, navigate to your domain dashboard. You'll see:
- DMARC Compliance Score - Percentage of email passing authentication (goal: 100%)
- SPF Status - Green (passing) or red (issues)
- DKIM Status - Green or red for all DKIM keys
- DNS Health - Overall DNS record validation
- Threat Summary - Count of suspicious/blocked senders
Your dashboard updates daily as new DMARC reports arrive.
Step 6: Explore the Dashboard
Domain Overview
The overview shows:
- Authentication stats (Pass/Fail/Neutral)
- Top senders by volume
- Top IPs sending from your domain
- Policy enforcement status
- Compliance timeline
Click any sender to see detailed information about their email patterns and authentication status.
Sender Discovery
Under "Email Sources," SpoofWard lists all senders found in your DMARC reports:
- Legitimate Senders - Services you authorized (green)
- Unknown Senders - Need investigation (yellow)
- Blocked Senders - Marked as suspicious (red)
Click each sender to:
- Verify it's legitimate
- Check SPF/DKIM alignment
- Block suspicious sources
- Add notes for your team
DNS Records
View your current DMARC, SPF, DKIM, MTA-STS, and BIMI records with validation status. If records are missing or invalid, SpoofWard highlights them and suggests fixes.
What's Next?
Congratulations! You're now monitoring your domain's email security. Here are recommended next steps:
- Authorize Senders - Review discovered senders and mark as legitimate or suspicious
- Review Reports - Check the "DMARC Reports" section to understand authentication patterns
- Strengthen SPF - Use the SPF Builder tool to create a properly formatted SPF record
- Check DKIM - Use the DKIM Checker tool to validate your DKIM keys
- Plan Enforcement - When you're ready, follow the DMARC Enforcement Roadmap to safely transition to p=quarantine and p=reject
Click "Team" in the left menu to invite colleagues. Assign roles (Owner, Admin, Analyst, Viewer) based on what they need to do.
Troubleshooting
Domain verification failed?
- Double-check the DNS record value (it's case-sensitive)
- Verify you're adding the TXT record to the correct domain
- Wait a few minutes and try again (DNS propagation takes time)
No DMARC reports showing up?
- Confirm your DMARC record has
rua=mailto:[email protected] - Send yourself a test email and wait 24-48 hours
- Check your DMARC record is at
_dmarc.yourdomain.com, not elsewhere
Can't see team members' data?
- Check your user role - Viewers have read-only access
- Admins and Owners can manage permissions
- You must be part of the same workspace
Check out more detailed guides on specific topics, or contact our support team. We're here to help!