DMARCLY

United States · dmarcly.com · 7 vendors

DMARCLY is a comprehensive email security solution that helps organizations protect their email domains from spoofing, phishing, and impersonation attacks. It provides tools for DMARC, SPF, and DKIM monitoring, reporting, and optimization. The platform aims to improve email deliverability and safeguard brand reputation.

Resilience scores

Technology vendors

Services catalogue

2 services in catalogue across 2 categories; runs on 7 sub-vendors.

Insights

Last updated 2026-08-15 · revision 2

7 direct vendors, 143 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 6/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

DMARCLY exhibits a medium level of migration readiness. The company's tech stack includes modern elements such as a REST API architecture, SAML-based SSO (integrating with Azure AD, Google, Okta), and Two-Factor Authentication (2FA), which are favorable for migration to modern cloud environments. The use of Cloudflare also suggests familiarity with external cloud services. However, the assessment is significantly hampered by a lack of critical information. There is no explicit mention of cloud-native adoption, containerization, or microservices architecture, which are key indicators of advanced migration readiness. Crucially, there is no data on the regulatory environment, data residency requirements, or financial stability (revenue, growth history), all of which are fundamental considerations for planning and funding a successful migration. The vendor relationship data is contradictory: 'Total Vendors: 0' is stated, but 'Total Services: 10' are listed with 'Vendor HQ Countries: Denmark, United States, France'. If DMARCLY truly has no external vendors, this would eliminate external vendor lock-in, but could imply high internal dependency. If the '10 services' represent actual vendor dependencies, the geographic diversity of their origins (3 countries) is a positive factor, potentially reducing complexity from a single region. However, the 'Vendor Lock-in Risk' remains unknown, and the exact number of distinct vendors for these services is not specified, making a precise lock-in assessment challenging. Overall, while the technical foundation is reasonable, the substantial gaps in financial, regulatory, and architectural details limit the current migration readiness.

Compliance

6 in-scope frameworks identified; showing 3.

GDPR (source) — Partially Compliant

DMARCLY explicitly claims GDPR compliance on its website footer and homepage ('We are GDPR compliant'), and provides a Data Processing Agreement (DPA) — both positive indicators. However, the privacy policy was last updated in September 2020, which is now significantly outdated and may not reflect current GDPR requirements (e.g., updated SCCs from 2021, evolving guidance on cookie consent, and data subject rights procedures). DMARCLY operates a dedicated EU data residency endpoint (eu.dmarcly.com) with servers in Frankfurt, Germany, demonstrating awareness of EU data localization obligations. The risk is Medium rather than High because structural compliance mechanisms (DPA, EU server option) are in place, but the age of the privacy policy and lack of a publicly named Data Protection Officer (DPO) introduce residual risk. GDPR fines can reach €20M or 4% of global annual turnover, making enforcement consequences severe. As a SaaS provider serving global customers including EU/EEA residents, GDPR is unambiguously applicable.

Evidence: https://dmarcly.com/privacy, https://dmarcly.com/Data_Processing_Agreement.pdf, https://dmarcly.com, https://eu.dmarcly.com/register

CAN-SPAM Act — Assessment Required

The CAN-SPAM Act (15 U.S.C. § 7701) governs commercial email communications in the United States. DMARCLY sends marketing communications to customers and prospects (referenced in the privacy policy). As a US-based company sending commercial emails, CAN-SPAM compliance is required. The risk is Low because CAN-SPAM requirements are relatively straightforward (unsubscribe mechanism, accurate headers, physical address), and DMARCLY's privacy policy references an opt-out mechanism for marketing communications. The company's core business (email authentication) suggests strong awareness of email standards.

Evidence: https://dmarcly.com/privacy, https://www.ftc.gov/business-guidance/resources/can-spam-act-compliance-guide-business

FTC Act — Assessment Required

The FTC Act Section 5 prohibits unfair or deceptive acts or practices, including misrepresentations about data security and privacy practices. DMARCLY's privacy policy claims 'reasonable steps to protect personal information' and the website claims GDPR compliance. The FTC has increasingly enforced against companies that make security claims without adequate substantiation. The risk is Medium because: (1) DMARCLY makes explicit security and GDPR compliance claims; (2) The privacy policy is significantly outdated (2020); (3) Use of third-party marketing cookies is described but consent mechanisms are not clearly articulated; (4) Any gap between stated and actual security practices could trigger FTC scrutiny. As a cybersecurity company, DMARCLY's security posture is subject to heightened scrutiny.

Evidence: https://dmarcly.com/privacy, https://www.ftc.gov/legal-library/browse/statutes/federal-trade-commission-act

Financials

Three-year financials

Financial Resilience Score: 4/10

DMARCLY is a small, private, US-based SaaS vendor in the DMARC/email authentication category with no publicly disclosed financial information. The company operates a recurring SaaS revenue model with monthly subscriptions ranging from $17.99 to $199 per month, which provides predictable cash flow once customers convert. Based on typical DMARC-SaaS competitive benchmarks, the company is likely in the low-single-digit millions USD ARR range, though this is inferred rather than disclosed. The company has credible marquee reference customers including Encyclopædia Britannica, Investopedia, IDC, the Academy Awards, Patreon, and Nissan, providing enterprise-grade credibility. Additionally, regulatory tailwinds from Google's and Yahoo's February 2024 bulk-sender rules requiring DMARC have expanded the addressable market. However, the company appears sub-scale relative to well-capitalized competitors like Valimail (>$85M raised), EasyDMARC (~$20M Series A), and Red Sift (>$70M raised). Key risks include no disclosed institutional funding limiting R&D capacity, commoditization risk as Cloudflare and Microsoft offer free/native DMARC reporting, key-person dependency on a very small leadership team, absence of SOC 2/ISO 27001 certifications that limit enterprise deal size, and complete lack of financial transparency which itself is a due-diligence risk factor.

Key strengths: Recurring SaaS subscription revenue model with predictable cash flow, Freemium tools generate low-cost customer acquisition via SEO, Marquee enterprise reference customers (Britannica, Investopedia, Oscars, Nissan, Patreon), Regulatory tailwind from Google/Yahoo Feb 2024 bulk-sender DMARC requirements, Lean, technical founding team suggesting low burn rate, Global SaaS delivery without physical footprint

Risk factors: Highly competitive niche with better-capitalized rivals (Valimail, Proofpoint, Cisco, Mimecast, Red Sift), No disclosed institutional funding limits R&D and enterprise sales investment, Commoditization risk from Cloudflare and Microsoft offering free DMARC reporting, Key-person dependency on small leadership team (CEO + CTO only named), No public evidence of SOC 2 or ISO 27001 certification limits enterprise deals, Complete lack of financial transparency, Unknown customer concentration and churn metrics

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report