DMARC-SRG is a basic, self-hosted PHP script. It parses aggregate (RUA) DMARC reports and presents them in a web-based interface. It offers a straightforward view of DMARC compliance, showing SPF and DKIM authentication results, and how emails align with your DMARC policy.
Its strength lies in its simplicity and directness, acting as a foundational tool for DMARC visibility. We find it to be a raw, unfiltered look at our DMARC data, which can be both a blessing and a curse depending on our analytical needs.
The Splunk TA-DMARC add-on is designed to ingest DMARC aggregate reports into Splunk, allowing us to leverage Splunk's powerful search, correlation, and dashboarding capabilities. It doesn't offer DMARC report parsing or presentation itself, but acts as a data pipeline.
Its value comes from integrating DMARC data into an existing Security Information and Event Management (SIEM) or observability platform for broader analysis. We see it as a connector, allowing us to weave DMARC insights into our wider security operations framework.
DMARC-SRG
How easy is each product to use
User experience
DMARC-SRG
Being a self-hosted PHP script, the DMARC-SRG user experience begins with server setup and configuration. This requires a certain level of technical proficiency and comfort with managing web applications.
Once deployed, the interface is functional but basic, focusing on displaying raw DMARC data with minimal interactive elements. It's a "no-frills" experience, best suited for those comfortable with managing their own web applications and who appreciate direct access to the parsed data. We appreciate its straightforward approach, even if it lacks modern UI polish.
The Splunk TA-DMARC add-on's user experience is entirely dependent on our Splunk environment. For those of us already familiar with Splunk, it's relatively easy to configure the add-on and build custom dashboards.
For new Splunk users, there's a significant learning curve for Splunk itself. The add-on provides the data; we build the visualization and interaction within Splunk, offering high customization but demanding Splunk expertise. It's a blank canvas, but we need to bring our own brushes and paint.
DMARC-SRG
Which product has the best support
Support
DMARC-SRG
As an open-source project, official support for DMARC-SRG is non-existent. We rely on community forums, GitHub issues, or our own technical skills for troubleshooting and enhancements.
This means "we break it, we bought it" troubleshooting, which can be a significant commitment of time and resources. There's no hotline to call, just our own problem-solving prowess.
The Splunk TA-DMARC add-on is explicitly marked as "Not Supported" and "archived" by the developer. This means there's no official channel for assistance or updates.
Users must be self-sufficient, relying on Splunk's general community support for Splunk issues, but not for the specific add-on's functionality. This makes us feel a bit like we're sailing without a rudder, hoping for favorable community winds.
DMARC-SRG
Who should use each product
Suitability
DMARC-SRG
DMARC-SRG is primarily suitable for individuals or small to medium businesses (SMBs) with technical expertise in server management and PHP. It's a cost-effective choice for those needing basic DMARC visibility without recurring subscription fees.
Managed Service Providers (MSPs) might find it useful if they can integrate and maintain it across multiple clients, but the lack of native multi-tenancy means significant manual effort. For enterprise use, it typically lacks the scalability, advanced features, and dedicated support required for complex DMARC deployments.
The Splunk TA-DMARC add-on is best suited for enterprises or larger organizations already heavily invested in Splunk as their SIEM or data analysis platform. It allows DMARC data to be correlated with other security logs for a holistic view.
SMBs would likely find the overhead of a Splunk instance disproportionate for DMARC alone. MSPs could potentially leverage Splunk's multi-tenant capabilities, but the add-on's "unsupported" status introduces substantial risk. Its archival status also makes it a less ideal choice for new deployments seeking long-term stability.
DMARC-SRG
How does DMARC-SRG compare with Splunk TA-DMARC add-on?
DMARC-SRG
DMARC report analysis
Parses and displays DMARC aggregate reports.
Parses RUA reports, presents basic compliance data
Ingests RUA reports into Splunk for analysis
Source detection
Identifies sending sources based on DMARC reports.
Basic identification from aggregate reports
Via Splunk's data analysis capabilities
Forward detection
Helps identify email forwarding patterns.
Basic, requires manual interpretation
Possible within Splunk, requires query creation
Spoof detection
Ability to identify email spoofing attempts.
Identifies non-compliant senders
Through DMARC policy enforcement data
Notifications and alerts
Automated alerts for DMARC issues.
No built-in alerting system
Leverages Splunk's native alerting features
Reporting
Generates summary or detailed reports.
Basic HTML summary reports
Customizable dashboards within Splunk
API
Application programming interface for integration.
Requires separate deployments or manual management
Can be configured within Splunk's multi-tenancy
SPF flattening
Tool for reducing SPF lookup count.
DMARC report analysis tools, not SPF management
DMARC report analysis tools, not SPF management
Hosted DMARC
A managed DMARC service.
Self-hosted PHP script
Splunk add-on
BIMI
Support for Brand Indicators for Message Identification.
No support for BIMI record management or reporting
No support for BIMI record management or reporting
MTA-STS/TLS-RPT
Support for secure email protocols.
No support for these protocols
No support for these protocols
Blocklists and reputation
Integration with email blocklists (or blacklists).
No integration
Can be integrated via Splunk lookups/apps
AI copilot
AI-powered assistance for DMARC management.
No AI features
No AI features
DNS monitoring
Monitors DNS records for DMARC changes.
Focuses on DMARC reports, not general DNS
Focuses on DMARC reports, not general DNS
Self hostable
Can be deployed on our own infrastructure.
Runs on your own PHP server
Runs within your Splunk instance
Free trial/free tier
Availability of a free version or trial period.
Completely free, open-source project
Free add-on (requires Splunk license)
Drawbacks and what to watch out for
DMARC-SRG's main drawbacks include its basic interface, lack of active development or formal support, and the requirement for manual hosting and maintenance. For Splunk TA-DMARC, the primary concerns are its "Not Supported" and "archived" status, meaning no official updates or assistance, and its reliance on a pre-existing Splunk deployment, which can be costly.
We have pulled the average ratings from G2 for each product, and also included the most recent negative reviews for each product in full. Positive reviews tend to have less detail and have a higher chance of being fraudulent, so negative reviews are a better signal for your decision.
DMARC-SRG
0 / 5(0)
0 / 5(0)
Pricing
DMARC-SRG is an entirely free, self-hosted open-source solution, while the Splunk TA-DMARC add-on is free to acquire but requires an existing Splunk license, which can carry significant costs.
DMARC-SRG
Small
Up to 10k emails / month
Free (self-hosted)
Free add-on (requires Splunk)
Medium
Up to 100k emails / month
Free (self-hosted)
Free add-on (requires Splunk)
Large
Up to 1 million emails / month
Free (self-hosted)
Free add-on (requires Splunk)
Enterprise
Over 1 million emails / month
Free (self-hosted)
Free add-on (requires Splunk)
Suped hard sell incoming!
Still not satisfied with DMARC-SRG or Splunk TA-DMARC add-on?