Policy hosting
A stable policy location for every managed domain.
A managed domain may publish an mta-sts CNAME to dmarc123.com so DMARC123 can serve the policy. Customers may instead route that hostname to their own server. In either model, the policy must remain available at /.well-known/mta-sts.txt with a valid certificate for the managed-domain hostname.
DNS validation
Compare expected records with public DNS.
DMARC123 checks the MTA-STS hostname route, policy TXT record, TLS-RPT TXT record, public policy URL, and policy content. The domain header reflects the current validation result rather than a separate workflow status.
TLS reporting
Keep aggregate totals separate from failure details.
Successful-session totals are displayed as aggregate evidence. Receiving MX, receiving IP, sending MTA IP, result type, and failed-session count appear only when the report actually contains failure-detail objects.