Dex
PowerDMARC logo
Security & Backup

PowerDMARC

Run your customers' email authentication from Dex - domain health, DMARC reports, and hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records.

Dex connects to PowerDMARC through the MSSP API so admins can manage email authentication conversationally - inventory domains, read health scores and DMARC aggregate reports, review the DNS-change timeline and alerts, run lookalike-domain scans and external analyzer checks, and update hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records. Because every write is an email-deliverability change, the record-changing actions require approval. PowerDMARC is an MSP global app: the partner holds one Personal Access Token on the master org and each customer maps to its own PowerDMARC MSSP account by numeric account id, so each tenant only ever sees its own domains. Employees can ask read-only questions like "why did my email go to spam?" through Dex Go without touching any settings.

What Dex does with PowerDMARC

Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.

A

For admins (Dex Pro)

  • Read a customer account overview - compliance percentages, security score, DMARC policy mix, and hosted-service coverage in one call
  • Inventory domains and read per-domain health, security score, and per-mechanism status
  • Read DMARC aggregate reports over an explicit date window to see who is sending as the customer
  • Review the DNS-change timeline, historical record values, and DNS, threshold, and forensic alerts
  • Run external analyzer checks on any domain, look up published DMARC records, and start lookalike/typosquat scans
  • Generate DMARC and BIMI record strings without publishing anything
  • Update hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records - with approval, because each is a deliverability change
  • Manage account members and, from the master connection, create accounts and onboard or remove domains - with approval
  • Deploy as an MSP global app - one partner token, each customer confined to its own PowerDMARC MSSP account by numeric account id
E

For employees (self-service)

  • Check whether your company's domain is protected from spoofing or only in monitoring mode
  • Understand why an email went to spam or got rejected
  • See whether a phishing message that looks like it's from your company would be blocked
  • Check whether an external supplier's domain is protected

Just ask Dex

Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.

Admin prompts

  • >Give me the PowerDMARC posture for Contoso - compliance percentages, security score, and policy mix
  • >Which of this customer's domains are still on p=none and give no spoofing protection?
  • >Show me the DMARC aggregate report for example.com over the last 30 days - who is sending as us?
  • >Any domain with an SPF lookup count at or above 8? That's close to the RFC limit
  • >Move example.com from p=none to quarantine at 25 percent after checking SPF and DKIM are valid

Employee prompts

  • >Is our domain protected from spoofing, or just monitoring?
  • >Why did my email go to spam?
  • >Someone is sending phishing that looks like it's from us - would it be blocked?
  • >Is this supplier's domain protected?

Policy actions

Every action Dex can take on PowerDMARC is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.

ActionWhat it does
powerdmarc_view_customer_overviewRead a customer account overview - compliance percentages, security score, policy mix, and hosted-service coverage
powerdmarc_view_customer_domains_overviewRead the per-domain overview rows for a customer account
powerdmarc_list_account_membersList the console logins inside one customer account
powerdmarc_view_account_memberRead one account member, including role and assigned domains
powerdmarc_add_account_memberCreate a console login inside a customer account
powerdmarc_remove_account_memberDelete a console login from a customer account
powerdmarc_list_accountsList every customer account in the partner console (partner-wide; refused on a tenant-scoped connection)
powerdmarc_create_accountCreate a new billable PowerDMARC customer account (partner-wide; refused on a tenant-scoped connection)
powerdmarc_list_domainsList an account's domains and their numeric ids
powerdmarc_view_domainRead one domain under an account
powerdmarc_view_domain_healthRead a domain's health - policy, security score, per-mechanism status, and remediation suggestions
powerdmarc_view_domain_reportsRead DMARC aggregate reporting for one domain over an explicit date window
powerdmarc_view_dns_changesRead the DNS-change timeline for a domain - who changed SPF/DKIM/DMARC and when
powerdmarc_view_security_scoreRead a domain's current security score
powerdmarc_view_records_historyRead a domain's historical DNS record values
powerdmarc_add_domainOnboard a domain under a PowerDMARC user (partner-wide; refused on a tenant-scoped connection)
powerdmarc_delete_domainRemove a domain from a user account - irreversible, discards reporting history and hosted records (partner-wide; refused on a tenant-scoped connection)
powerdmarc_view_hosted_dmarcRead a domain's hosted DMARC record
powerdmarc_update_hosted_dmarcSet a domain's hosted DMARC record - replaces the record; raising the policy or percentage can start blocking legitimate mail
powerdmarc_view_hosted_spfRead a domain's hosted SPF record, including the DNS lookup count
powerdmarc_update_hosted_spfAdd or remove one mechanism on a domain's hosted SPF record - a wrong edit or crossing the 10-lookup limit breaks SPF for every recipient
powerdmarc_view_hosted_dkimRead a domain's hosted DKIM selectors
powerdmarc_create_dkim_selectorPublish a new hosted DKIM selector for a domain
powerdmarc_view_hosted_bimiRead a domain's hosted BIMI record
powerdmarc_update_hosted_bimiSet a domain's hosted BIMI logo/VMC
powerdmarc_view_mta_sts_policyRead a domain's hosted MTA-STS policy
powerdmarc_update_mta_sts_policyReplace a domain's hosted MTA-STS policy text
powerdmarc_update_mta_sts_modeSet a domain's MTA-STS mode - enforce on an unverified policy blocks inbound mail to the customer
powerdmarc_reset_mta_sts_policyReset a domain's MTA-STS policy to the default, discarding the current policy
powerdmarc_list_account_alertsList a customer account's DNS, threshold, and forensic alerts
powerdmarc_analyze_domainRun the external analyzer on any domain (read-only DNS check - SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT)
powerdmarc_export_domain_analysisExport a domain analysis as PDF (read-only)
powerdmarc_lookup_dmarc_recordLook up the published DMARC record for one or more domains (read-only DNS lookup)
powerdmarc_start_lookalike_scanStart a lookalike/typosquat domain scan (read-only; returns a job id)
powerdmarc_view_lookalike_resultsRead the results of a lookalike domain scan by job id
powerdmarc_generate_dmarc_recordGenerate a DMARC record string from parameters (read-only; publishes nothing)
powerdmarc_generate_bimi_recordGenerate a BIMI record string from parameters (read-only; publishes nothing)

How to configure PowerDMARC

Onboarding takes minutes. Dex validates your credentials before saving them.

Setup steps

  1. 1
    In the PowerDMARC console, go to API settings > Manage API Tokens > Generate new token and select every permission the integration needs (permissions cannot be added later, and the token is shown once).
  2. 2
    Note your console hostname - app.powerdmarc.com for a direct account, or <partner>.powerdmarc.com for an MSSP partner console (only *.powerdmarc.com hosts are accepted).
  3. 3
    In Dex, enable the PowerDMARC integration and paste the API token and console host. Leave account_id empty on the MSP master connection for partner-wide access.
  4. 4
    Dex validates the token with a live call to /api/v1/me before saving.
  5. 5
    For MSPs, map each child tenant to its numeric PowerDMARC MSSP account id from GET /api/v1/mssp/accounts on the master connection - an account name or e-mail is not accepted.

Credentials required

api_token
PowerDMARC Personal Access Token, permission-scoped at creation and shown once
mssp_host
Console hostname without https:// or a path - app.powerdmarc.com or <partner>.powerdmarc.com (blank defaults to app.powerdmarc.com)
account_id
Numeric PowerDMARC MSSP account id for this tenant - leave empty on the master connection for partner-wide access (per-customer MSP isolation)

Requirements

  • A PowerDMARC account with MSSP API access and a permission-scoped Personal Access Token
  • A *.powerdmarc.com console host - white-label consoles on your own domain are not supported by this connection
  • DKIM-selector edit/delete and domain onboarding/removal are master-only and refused on tenant-scoped connections
  • BIMI editing may only accept the URL form since the endpoint is declared as multipart/form-data; a 423 Locked on a hosted-record write means DNS is not delegated to PowerDMARC yet
  • For MSPs, the integration deploys as a global app with per-tenant scoping by numeric MSSP account id

See Dex run PowerDMARC

Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.