Features Pricing
Free Tools
DMARC Checker SPF Checker DKIM Checker Domain Scanner Blacklist Checker Header Analyzer All 11 tools →
Resources
What is DMARC? What is SPF? What is DKIM? What is BIMI? Academy Blog Docs MSP Program Contact
Sign in Start →

T&C Pulse Integration

T&C Pulse can show your customers' email security — SPF, DKIM, DMARC, open findings and the DNS health score for every domain — in its security summary, with a link back to SpoofWard for the fix. Pulse only reads. It cannot change a domain, a DNS record or a setting in SpoofWard, and SpoofWard stays the source of truth.

Who can set this up

A workspace owner or admin, with two-factor authentication turned on. Your plan must include API access.

Connect in three steps

  1. Create a Pulse token. In SpoofWard go to Settings → Integrations → T&C Pulse and click Create Pulse token. Confirm your password when asked. The token is read-only (the single domains:read ability) and is valid for one year. Copy it straight away — it is shown only once.
  2. Connect SpoofWard in Pulse. In Pulse open Integrations → SpoofWard → Connect SpoofWard. Paste the address shown on the SpoofWard card (https://spoofward.com/api) and the token, then click Send test.
  3. Match your customers. Pulse lists every SpoofWard customer it found. Choose the Pulse organization for each one, then switch the connection on.

Which domains Pulse sees

  • Every domain in the workspace the token was created in, including domains that are not verified or not checked yet (their status shows as unknown until the first check).
  • For an MSP workspace, also every domain in the MSP's active or suspended client workspaces, so one token covers all your customers.
  • Never a domain from any other workspace.

How customers are reported

Each domain is reported with the customer it belongs to:

  • A domain in a client workspace (MSP Portal) belongs to that client.
  • A domain in your own workspace belongs to your workspace — unless you assign it to a customer. Open the domain, find the Customer card, type the customer's name (or pick one you used before) and click Save customer. Domains with the same customer name are grouped together.
Tip for MSPs

If you keep several customers' domains in your own workspace, assign each domain a customer before you connect Pulse. Otherwise they all arrive in Pulse as one customer.

What Pulse receives for each domain

ItemMeaning
SPF, DKIM, DMARC statusok, warning (published but weak, e.g. SPF ~all, DMARC p=none, a DKIM key under 2048 bits), failing (published but broken), missing, or unknown (not checked yet).
DMARC policyThe published p= value: none, quarantine or reject.
ScoreThe DNS health score from 0 to 100, as on the domain page.
FindingsThe issues open right now, in plain language (at most 25 per domain). Fixed issues disappear at the next check.
Last checkedWhen SpoofWard last checked the domain's DNS.

Keeping the connection working

  • The T&C Pulse card shows when Pulse last read the data and from which IP address.
  • The token expires after one year. SpoofWard emails the person who created it 30 days and 7 days before. Create a new token on the card, paste it into Pulse, then revoke the old one under Settings → API.
  • To disconnect Pulse, revoke its token under Settings → API. Pulse stops reading immediately.

For developers

Pulse calls GET https://spoofward.com/api/pulse/v1/domains?limit=200 with Authorization: Bearer <token>, follows the next cursor until it is null, and never follows redirects. Any token with the read or domains:read ability works. See API Tokens for rate limits.

Your domain is being tested right now.
Are you watching?

Protect your brand and improve deliverability — automatically, with continuous monitoring and alerts.