PowerDMARC
Run your customers' email authentication from Dex - domain health, DMARC reports, and hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records.
Dex connects to PowerDMARC through the MSSP API so admins can manage email authentication conversationally - inventory domains, read health scores and DMARC aggregate reports, review the DNS-change timeline and alerts, run lookalike-domain scans and external analyzer checks, and update hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records. Because every write is an email-deliverability change, the record-changing actions require approval. PowerDMARC is an MSP global app: the partner holds one Personal Access Token on the master org and each customer maps to its own PowerDMARC MSSP account by numeric account id, so each tenant only ever sees its own domains. Employees can ask read-only questions like "why did my email go to spam?" through Dex Go without touching any settings.
What Dex does with PowerDMARC
Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.
For admins (Dex Pro)
- Read a customer account overview - compliance percentages, security score, DMARC policy mix, and hosted-service coverage in one call
- Inventory domains and read per-domain health, security score, and per-mechanism status
- Read DMARC aggregate reports over an explicit date window to see who is sending as the customer
- Review the DNS-change timeline, historical record values, and DNS, threshold, and forensic alerts
- Run external analyzer checks on any domain, look up published DMARC records, and start lookalike/typosquat scans
- Generate DMARC and BIMI record strings without publishing anything
- Update hosted DMARC, SPF, DKIM, BIMI, and MTA-STS records - with approval, because each is a deliverability change
- Manage account members and, from the master connection, create accounts and onboard or remove domains - with approval
- Deploy as an MSP global app - one partner token, each customer confined to its own PowerDMARC MSSP account by numeric account id
For employees (self-service)
- Check whether your company's domain is protected from spoofing or only in monitoring mode
- Understand why an email went to spam or got rejected
- See whether a phishing message that looks like it's from your company would be blocked
- Check whether an external supplier's domain is protected
Just ask Dex
Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.
Admin prompts
- >Give me the PowerDMARC posture for Contoso - compliance percentages, security score, and policy mix
- >Which of this customer's domains are still on p=none and give no spoofing protection?
- >Show me the DMARC aggregate report for example.com over the last 30 days - who is sending as us?
- >Any domain with an SPF lookup count at or above 8? That's close to the RFC limit
- >Move example.com from p=none to quarantine at 25 percent after checking SPF and DKIM are valid
Employee prompts
- >Is our domain protected from spoofing, or just monitoring?
- >Why did my email go to spam?
- >Someone is sending phishing that looks like it's from us - would it be blocked?
- >Is this supplier's domain protected?
Policy actions
Every action Dex can take on PowerDMARC is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.
| Action | What it does |
|---|---|
powerdmarc_view_customer_overview | Read a customer account overview - compliance percentages, security score, policy mix, and hosted-service coverage |
powerdmarc_view_customer_domains_overview | Read the per-domain overview rows for a customer account |
powerdmarc_list_account_members | List the console logins inside one customer account |
powerdmarc_view_account_member | Read one account member, including role and assigned domains |
powerdmarc_add_account_member | Create a console login inside a customer account |
powerdmarc_remove_account_member | Delete a console login from a customer account |
powerdmarc_list_accounts | List every customer account in the partner console (partner-wide; refused on a tenant-scoped connection) |
powerdmarc_create_account | Create a new billable PowerDMARC customer account (partner-wide; refused on a tenant-scoped connection) |
powerdmarc_list_domains | List an account's domains and their numeric ids |
powerdmarc_view_domain | Read one domain under an account |
powerdmarc_view_domain_health | Read a domain's health - policy, security score, per-mechanism status, and remediation suggestions |
powerdmarc_view_domain_reports | Read DMARC aggregate reporting for one domain over an explicit date window |
powerdmarc_view_dns_changes | Read the DNS-change timeline for a domain - who changed SPF/DKIM/DMARC and when |
powerdmarc_view_security_score | Read a domain's current security score |
powerdmarc_view_records_history | Read a domain's historical DNS record values |
powerdmarc_add_domain | Onboard a domain under a PowerDMARC user (partner-wide; refused on a tenant-scoped connection) |
powerdmarc_delete_domain | Remove a domain from a user account - irreversible, discards reporting history and hosted records (partner-wide; refused on a tenant-scoped connection) |
powerdmarc_view_hosted_dmarc | Read a domain's hosted DMARC record |
powerdmarc_update_hosted_dmarc | Set a domain's hosted DMARC record - replaces the record; raising the policy or percentage can start blocking legitimate mail |
powerdmarc_view_hosted_spf | Read a domain's hosted SPF record, including the DNS lookup count |
powerdmarc_update_hosted_spf | Add or remove one mechanism on a domain's hosted SPF record - a wrong edit or crossing the 10-lookup limit breaks SPF for every recipient |
powerdmarc_view_hosted_dkim | Read a domain's hosted DKIM selectors |
powerdmarc_create_dkim_selector | Publish a new hosted DKIM selector for a domain |
powerdmarc_view_hosted_bimi | Read a domain's hosted BIMI record |
powerdmarc_update_hosted_bimi | Set a domain's hosted BIMI logo/VMC |
powerdmarc_view_mta_sts_policy | Read a domain's hosted MTA-STS policy |
powerdmarc_update_mta_sts_policy | Replace a domain's hosted MTA-STS policy text |
powerdmarc_update_mta_sts_mode | Set a domain's MTA-STS mode - enforce on an unverified policy blocks inbound mail to the customer |
powerdmarc_reset_mta_sts_policy | Reset a domain's MTA-STS policy to the default, discarding the current policy |
powerdmarc_list_account_alerts | List a customer account's DNS, threshold, and forensic alerts |
powerdmarc_analyze_domain | Run the external analyzer on any domain (read-only DNS check - SPF, DKIM, DMARC, BIMI, MTA-STS, TLS-RPT) |
powerdmarc_export_domain_analysis | Export a domain analysis as PDF (read-only) |
powerdmarc_lookup_dmarc_record | Look up the published DMARC record for one or more domains (read-only DNS lookup) |
powerdmarc_start_lookalike_scan | Start a lookalike/typosquat domain scan (read-only; returns a job id) |
powerdmarc_view_lookalike_results | Read the results of a lookalike domain scan by job id |
powerdmarc_generate_dmarc_record | Generate a DMARC record string from parameters (read-only; publishes nothing) |
powerdmarc_generate_bimi_record | Generate a BIMI record string from parameters (read-only; publishes nothing) |
How to configure PowerDMARC
Onboarding takes minutes. Dex validates your credentials before saving them.
Setup steps
- 1In the PowerDMARC console, go to API settings > Manage API Tokens > Generate new token and select every permission the integration needs (permissions cannot be added later, and the token is shown once).
- 2Note your console hostname - app.powerdmarc.com for a direct account, or <partner>.powerdmarc.com for an MSSP partner console (only *.powerdmarc.com hosts are accepted).
- 3In Dex, enable the PowerDMARC integration and paste the API token and console host. Leave account_id empty on the MSP master connection for partner-wide access.
- 4Dex validates the token with a live call to /api/v1/me before saving.
- 5For MSPs, map each child tenant to its numeric PowerDMARC MSSP account id from GET /api/v1/mssp/accounts on the master connection - an account name or e-mail is not accepted.
Credentials required
- api_token
- PowerDMARC Personal Access Token, permission-scoped at creation and shown once
- mssp_host
- Console hostname without https:// or a path - app.powerdmarc.com or <partner>.powerdmarc.com (blank defaults to app.powerdmarc.com)
- account_id
- Numeric PowerDMARC MSSP account id for this tenant - leave empty on the master connection for partner-wide access (per-customer MSP isolation)
Requirements
- •A PowerDMARC account with MSSP API access and a permission-scoped Personal Access Token
- •A *.powerdmarc.com console host - white-label consoles on your own domain are not supported by this connection
- •DKIM-selector edit/delete and domain onboarding/removal are master-only and refused on tenant-scoped connections
- •BIMI editing may only accept the URL form since the endpoint is declared as multipart/form-data; a 423 Locked on a hosted-record write means DNS is not delegated to PowerDMARC yet
- •For MSPs, the integration deploys as a global app with per-tenant scoping by numeric MSSP account id
Related integrations
- Security & Backup
DNSFilter
Run protective DNS from chat - review and change filtering policies, allow/block lists, sites, and roaming clients, with every change held for approval.
Learn more → - Directory & Identity
Microsoft Entra ID
Manage Entra ID users, groups, licenses, and sign-in risk through Microsoft Graph.
Learn more → - Collaboration
Exchange Online
Manage shared mailboxes, distribution lists, aliases, and mailbox delegation.
Learn more →
See Dex run PowerDMARC
Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.