Open-source, self-hosted DMARC monitoring for agencies - unlimited domains, no per-domain pricing.
10K+
Open-source, self-hosted DMARC monitoring for agencies. Point it at the mailbox
your rua= reports arrive in and it collects, parses and charts them — unlimited
domains, many clients, no per-domain pricing, and the report data never leaves
your infrastructure.
Documentation · Install guide · Source
mkdir dmarc-analyzer && cd dmarc-analyzer
curl -fsSL -o compose.yml https://raw.githubusercontent.com/dmarc-analyzer-net/DmarcAnalyzerApp/main/deploy/compose.yml
echo "DMARC_ENCRYPTION_KEY=$(openssl rand -base64 32)" > .env
docker compose up -d
Open http://localhost:8080 and create the first administrator account. Two containers: this one, and PostgreSQL.
Keep
DMARC_ENCRYPTION_KEYsafe and backed up — it decrypts your stored mailbox passwords. Lose it and every mailbox source has to be re-entered.
One image, selected with APP_MODE:
| Value | Runs |
|---|---|
all | console and report ingestion in one process — what the compose file uses |
api | console only |
worker | ingestion only |
migrate | applies pending database migrations and exits |
Any other value fails startup rather than falling back, so a typo cannot leave you with a container that serves the console and quietly ingests nothing.
Only one ingestion worker may run against a database. The process takes a PostgreSQL advisory lock and a second worker exits rather than duplicating every sync pass.
Environment variables, the same set here and on Kubernetes. The complete list is in the configuration reference. The two that matter on day one:
| Variable | |
|---|---|
ConnectionStrings__Default | Npgsql connection string |
DATABASE_URL | postgres://user:pass@host/db instead, if your platform sets it |
Security__CredentialEncryptionKey | base64 32 bytes; openssl rand -base64 32 |
latest tracks releases. Pin a version (0.13.0) for anything you depend on —
it makes upgrades explicit and rollbacks unambiguous. edge tracks main and is
unreleased.
Built for linux/amd64 and linux/arm64, so a Raspberry Pi or Apple Silicon
machine works.
ghcr.io/dmarc-analyzer-net/dmarc-analyzer, no anonymous pull rate limitsoci://ghcr.io/dmarc-analyzer-net/charts/dmarc-analyzerApache-2.0. Issues and questions: github.com/dmarc-analyzer-net/DmarcAnalyzerApp/issues
Content type
Image
Digest
sha256:fa9c35c2f…
Size
109.1 MB
Last updated
5 days ago
docker pull dmarcanalyzernet/dmarc-analyzer