TrustHeader

Self-hostable · under active development

Ingest, assess, report

TrustHeader ingests DMARC aggregate and failure reports and SMTP TLS reports, archives the original payload, and runs authentication and hygiene checks against it.

A skipped check is never a pass.

Every finding shows how it was derived, and a check that could not run is reported as skipped and left out of the score. A report is an observation from the reporters that send one, not proof a domain is safe everywhere.

Latest assessment

example.com2026-08-28 06:00Z

Checks

12

Pass

9

Warn

1

Fail

1

Skipped

1

Domain Check Verdict Derivation Findings
example.com DKIM signature ■ PASS
example.com MTA-STS policy ■ PASS
mail.example.com DMARC policy ◆ WARN p=none inherited from org domain
example.com DANE ● FAIL no TLSA record at mx2
example.com BIMI □ SKIPPED no VMC published, so the check could not run
□ Skipped

No VMC is published, so the BIMI check could not run. It is reported as skipped and left out of the score, which is not the same as passing.

Showing 5 of 12 checks.

What it does

Three surfaces

They are kept structurally separate, so the parts mail infrastructure can reach never touch the authenticated dashboard.

01

Ingest

Report ingest and archive

Reports arrive by email or over HTTPS and land in an immutable raw archive before anything is parsed. Failure-sensitive raw messages expire on a bounded window; everything else stays rebuildable.

DMARC aggregate and failure reports over email

SMTP TLS reports over email and HTTPS

Duplicate reports suppressed by the database, not guesswork

02

Assess

Assessment checks

Modules cover DMARC, SPF, DKIM, DNSSEC, MX hygiene, MTA-STS, TLS reporting, DANE and BIMI. A skipped check is never counted as a pass.

Pass, fail, warn, info, skipped and error kept distinct

Sending sources enriched with rDNS, FCrDNS and ASN

An optional external prober supplies live SMTP evidence

03

Serve

Hosted policy and endpoints

The anonymous surfaces mail infrastructure needs to reach run apart from the dashboard, so nothing public can see tenant report data.

Hosted MTA-STS policy at /.well-known/mta-sts.txt

TLS reports accepted at POST /v1/tls

An authenticated API and dashboard for report detail

How it works

Three steps

Point your domain at TrustHeader and reports start arriving.

01

Add the records

Publish the DMARC, MTA-STS and TLS reporting records that point at TrustHeader for each domain you monitor.

02

Update the records

Change policy or reporting addresses as your setup changes; TrustHeader keeps receiving.

03

Get reporting data

Reports get parsed, assessed and stored, ready to view in the dashboard or pull from the API.

TrustHeader is under active development

The repository is private and the platform is not yet generally available. There is no signup, no trial and no pricing.