LetsDMARC vs.
Splunk TA-DMARC add-on in 2026

LetsDMARC

Splunk TA-DMARC add-on
vs.
We tested LetsDMARC and the Splunk TA-DMARC add-on for 90 days across a corporate domain, a marketing subdomain, a parked domain, and five approved sending services. LetsDMARC gave us the faster route to classified sources and policy enforcement, while TA-DMARC gave Splunk operators flexible raw data but left more DMARC work to searches, rules, and internal runbooks.
Published 6 Nov 2025
Updated 20 Aug 2026
8 min read
Summarize with
LetsDMARC
Managed DMARC enforcement
Starts at
From £264 / year
Best fit
Enterprises and MSPs wanting guided DMARC operations
In one line
LetsDMARC turned our approved senders, spoof sample, and DNS changes into a usable enforcement plan, but exact package limits required a quote.
Splunk TA-DMARC add-on
Self-hosted DMARC data ingestion
Starts at
$0 add-on; Splunk required
Best fit
Existing Splunk teams with engineering capacity
In one line
TA-DMARC parsed our reports reliably but needed manual searches and ownership work; Suped has published starter pricing for teams prioritising guided ownership.
Suped
The better option. Hosted SPF, DMARC, and MTA-STS on every plan. Published pricing. Monthly plans. No long contract required.
Learn about Suped
Pick LetsDMARC for guided enforcement, TA-DMARC for Splunk-native control
Pick LetsDMARC if
Teams that want a managed path to DMARC enforcement
Three domains onboarded in 58 minutes
Named all five approved senders
Policy view exposed the spoof sample
From £264 / year
Pick Splunk TA-DMARC add-on if
Splunk operators willing to build the DMARC workflow
Parsed all seven authentication cases
Used existing Splunk role boundaries
Required manual sender owner classification
$0 add-on; Splunk required
Consider Suped if
The third option for guided fixes, hosted records, and simpler ownership
Guided fixes map findings to DNS changes
Automated detection reduces alert triage
MSP workflows start at $7 per domain
Free plan available
The differences that actually change your week
LetsDMARC
Splunk TA-DMARC add-on
Suped
DMARC report analysis
Turns aggregate XML into authentication results and usable views.
Dashboard analysis with source and policy drilldowns
Parsed events analysed through Splunk searches
Dashboard analysis and drilldowns
Source detection
Identifies the services or infrastructure sending for a domain.
Named service classification with owner workflow
IP and reverse DNS resolution; classification is manual
Named source identification
Forward detection
Separates forwarding effects from direct authentication faults.
Forwarding context appears in report analysis
No dedicated forward detection; manual interpretation
Forwarding context included
Spoof detection
Surfaces unauthorised mail that fails aligned authentication.
Unauthorised traffic and lookalike workflows
Search and alert rule required
Spoof detection and alerts
Notifications and alerts
Routes material authentication or DNS changes to operators.
Built-in alerts with Slack and Teams channels
Uses Splunk alert rules and integrations
Configurable operational alerts
Reporting
Produces recurring or exportable DMARC summaries.
Dashboard reports and exports
Search-driven dashboards and scheduled reports
Scheduled reports and exports
API
Supports programmatic administration or data access.
Administrative API for domains, hosted DNS, and alerts
Available through Splunk platform APIs
API available
Multi-tenancy
Separates domains, operators, or clients within one service.
Parent and child tenants for MSP use
Manual separation through indexes, roles, and apps
MSP workspaces and client separation
SPF flattening
Manages SPF lookup pressure with a flattened record workflow.
Hosted SPF flattening available; tier unclear
Reporting only
Hosted SPF flattening
Hosted DMARC
Publishes and manages the DMARC record for the customer.
Managed DNS publishing available
No hosted DMARC workflow
Managed DMARC record
Hosted SPF
Publishes and maintains SPF through a managed record.
Managed SPF available
No hosted SPF workflow
Managed SPF record
Hosted MTA-STS
Hosts the MTA-STS policy and supports TLS reporting operations.
TLS reporting available; hosted MTA-STS not established
No hosted MTA-STS workflow
Hosted policy and TLS reports
Blocklists and reputation
Monitors blocklist or blacklist status and sender reputation.
No dedicated blocklist or blacklist monitor found
No dedicated blocklist or blacklist monitor
Blocklist, blacklist, and reputation monitoring
Automatic issue detection
Finds policy, DNS, or sending changes without a manual query.
Automated DNS, policy, and quota alerts
Manual searches and custom rules required
Automatic issue detection
AI copilot
Provides conversational analysis or generated remediation guidance.
No AI copilot found
No DMARC-specific AI copilot
AI-assisted investigation
DNS monitoring
Tracks authentication record changes over time.
DNS timeline for DMARC, DKIM, SPF, and MX
No dedicated DNS monitoring
Authentication DNS monitoring
Self hostable
Can run within customer-controlled infrastructure.
On-premise deployment is offered
Runs with self-hosted Splunk Enterprise
Cloud service
Free trial/free tier
Allows evaluation without buying a production subscription.
30-day free trial; no free plan found
$0 add-on; Splunk entitlement still required
Free plan available
Ten dimensions, scored from 0 to 10
We scored both products against a fixed editorial rubric based on our 90-day test. Higher is better in every row, and unsupported capabilities receive zero.
LetsDMARC leads on managed enforcement; TA-DMARC remains useful for Splunk-led operations
LetsDMARC classified Microsoft 365, Google Workspace, SendGrid, Mailchimp, and the support desk sender with less manual work, then connected the spoof finding to policy movement. TA-DMARC parsed every controlled case, but the forwarded SPF failure and unknown sender needed saved searches plus analyst interpretation. Splunk alert routing was flexible once configured, while the archived add-on had no dedicated support or hosted authentication records.
LetsDMARC score
66/100
Splunk TA-DMARC add-on score
32.5/100
LetsDMARC
66/100
DMARC enforcement
8.5
Customer support
8.5
Source resolution
8.0
Setup and onboarding
8.0
MSP workflows
7.5
Alerting and integrations
7.5
Hosted SPF and MTA-STS
6.5
Blocklist monitoring
0.0
Pricing transparency
3.5
Time to enforcement
8.0
Splunk TA-DMARC add-on
32.5/100
DMARC enforcement
4.5
Customer support
0.0
Source resolution
4.5
Setup and onboarding
4.0
MSP workflows
4.5
Alerting and integrations
7.5
Hosted SPF and MTA-STS
0.0
Blocklist monitoring
0.0
Pricing transparency
4.0
Time to enforcement
3.5
Feature set
Guidance vs raw control
LetsDMARC owns more of the DMARC job
LetsDMARC covered classification, policy movement, managed records, and DNS monitoring in one workflow. TA-DMARC covered ingestion and exposed the raw evidence, but we had to build more of the operating layer. We would keep guided fixes and automatic issue detection on the buying checklist; Suped includes both for teams that do not want each finding to become a manual project.
LetsDMARC

Named Microsoft 365 correctly
Separated SendGrid and Mailchimp
Flagged visible-from mismatch
Splunk TA-DMARC add-on

Parsed Google Workspace XML
Resolved unknown sender IP
Exposed forwarded SPF failure
LetsDMARC named Microsoft 365, Google Workspace, SendGrid, Mailchimp, and our support desk sender after we approved them. It separated the aligned SPF pass from the marketing subdomain's DKIM pass, showed the visible-from mismatch as unaligned, and gave the unauthorised spoof sample a clear owner action. The unknown sender still needed our confirmation, but service clues and report drilldowns shortened that work.
TA-DMARC ingested all seven controlled cases and made the underlying XML fields searchable. We built searches that separated SendGrid and Mailchimp, found Google Workspace traffic, preserved the subdomain DKIM result, and exposed the forwarded message with SPF failure. The add-on resolved the unknown source IP, but naming its service and turning the result into a DMARC change remained our responsibility.
User experience
Guided flow vs operator console
LetsDMARC made the test easier to explain and repeat
LetsDMARC gave each domain a recognisable setup and classification flow, so another operator could retrace our decisions. TA-DMARC fit Splunk habits well, but its usability depended on the searches, field knowledge, and dashboards we supplied.
LetsDMARC

Three domains in 58 minutes
Unknown sender had context
Forwarding explanation stayed clear
Splunk TA-DMARC add-on

Setup took 2h 40m
Unknown sender needed pivots
Forwarding needed analyst notes
We added the corporate domain, marketing subdomain, and parked domain in 58 minutes, including verification and initial DNS checks. LetsDMARC grouped their states clearly, put the unknown sender beside source evidence, and explained the forwarded SPF failure without presenting it as a simple spoof. Switching pages reset a few display choices, but it did not block the investigation.
We spent 2 hours 40 minutes installing TA-DMARC, connecting the report mailbox, validating parsing, and building the first useful searches for all three domains. Finding the unknown sender meant pivoting across source IP, reverse DNS, and authentication fields. The forwarded SPF failure was visible, but we had to explain forwarding and DKIM survival in our own dashboard notes.
Support
Product help vs internal ownership
LetsDMARC has the safer support handoff
LetsDMARC gave us a defined path for setup questions, DNS handoff, and escalation. TA-DMARC is archived and marked not supported, so its operational safety depends on the team's Splunk and DMARC skills.
LetsDMARC

DNS handoff checklist was usable
Escalation answered same business day
Enterprise roles were explained clearly
Splunk TA-DMARC add-on

Add-on marked not supported
DNS guidance stayed operator-owned
Platform escalation excluded add-on
During setup, LetsDMARC guidance covered domain verification and the DNS records our administrator needed to publish. Our test escalation about the support desk sender received a useful answer the same business day, and the enterprise onboarding path explained roles and deployment choices. We still needed a commercial conversation to confirm support entitlement and package limits.
TA-DMARC gave us documentation and source code, but no maintained add-on support channel. We owned mailbox authentication, DNS interpretation, parser troubleshooting, and the support handoff ourselves. A Splunk platform escalation could address the underlying deployment, but it did not cover DMARC policy advice or the archived add-on's custom searches.
Suitability
Managed fit vs engineering fit
LetsDMARC fits DMARC teams; TA-DMARC fits Splunk builders
LetsDMARC is the clearer fit for an enterprise or MSP that wants domain grouping, account separation, and client-ready reporting. TA-DMARC makes sense when Splunk is already the operating console and engineering time is available. We would also test MSP account separation and alert quality at client scale; Suped makes those workflows explicit instead of relying on manually designed indexes and searches.
LetsDMARC

Parent-child tenants separated accounts
Domain groups simplified reporting
Exports supported client handoff
Splunk TA-DMARC add-on

Indexes separated client data
Recurring reports needed searches
Client handoff needed runbooks
LetsDMARC kept the corporate domain, marketing subdomain, and parked domain in one policy view while preserving domain-level status. Parent and child tenant concepts supported MSP account separation, and exports gave us a workable client handoff. An SMB can use the guided flow, but unclear volume bands and package limits make procurement less predictable.
TA-DMARC suited our enterprise Splunk operator once we assigned indexes, roles, domain tags, and scheduled searches. Those controls separated client data, but recurring reporting and handoff notes were custom work. For an MSP with many clients or an SMB without a Splunk team, that maintenance burden outweighs the add-on's $0 license.
What each tool feels like after 90 days of real use
What LetsDMARC felt like after 90 days of real use
LetsDMARC
After 90 days, LetsDMARC felt like a DMARC operating product rather than a report viewer. We could move between the corporate domain, marketing subdomain, and parked domain, see which approved service owned traffic, and keep the unauthorised spoof sample separate from the forwarded SPF failure.
The strongest daily benefit was continuity: policy status, source classification, DNS history, and alerts stayed connected. The recurring friction was commercial and administrative, because public pricing did not explain volume bands, retention, or which hosted capabilities sat in each package.
Where it wins
Classified all five approved senders
Connected findings to policy movement
Preserved DNS change history
Supported parent and child tenants
Where it lags
Exact plan limits stayed unpublished
Hosted MTA-STS was not established
No dedicated blocklist monitoring
Some display settings reset
Pricing
From £264 / year
Free tier
No; 30-day trial
Onboarding
3 domains in 58 minutes
G2 rating
4.5 / 5
What Splunk TA-DMARC add-on felt like after 90 days of real use
Splunk TA-DMARC add-on
After 90 days, TA-DMARC felt dependable as an ingestion component. It parsed the controlled cases, exposed fields for our own searches, and let the Splunk team route alerts through its existing operating model.
The cost was sustained ownership. We maintained sender mappings, forwarding notes, saved searches, role boundaries, scheduled reports, and client handoff documentation. Because the add-on is archived and not supported, each change needed internal testing before we trusted it in the recurring workflow.
Where it wins
Parsed every controlled report case
Fit existing Splunk alert routing
Allowed custom search logic
Kept the add-on license free
Where it lags
Archived and not supported
Source ownership stayed manual
No hosted authentication records
Recurring reports required maintenance
Pricing
$0 add-on; Splunk required
Free tier
Free add-on only
Onboarding
3 domains in 2h 40m
G2 rating
0 / 5
Pricing
LetsDMARC
Splunk TA-DMARC add-on
Suped
Small
1 domain, up to 1k emails / month.
From £264 / year
Public directory starting price; included domain and volume limits are not published.
$0 add-on
MIT-licensed add-on; a Splunk platform entitlement and operating capacity are still required.
$0 / month
Free plan covers 1 domain and 1,000 monthly emails.
Medium
2 domains, up to 100k emails / month.
Not publicly listed as of May 15, 2026
The official quote uses mailbox count, deployment, and licensed message volume.
$0 add-on
The add-on has no DMARC volume tier; Splunk ingestion or workload cost applies.
Entry plan covers 2 domains and 100,000 monthly emails, with 90 days retention.
Large
10 domains, up to 1 million emails / month.
Not publicly listed as of May 15, 2026
Public material does not map this volume to a named plan or overage rate.
$0 add-on
Storage, retention, parsing, searches, and platform capacity determine the real cost.
10 domains and 1,000,000 monthly emails, with 365 days retention.
Enterprise
Over 20 domains and 1 million emails / month.
Not publicly listed as of May 15, 2026
Deployment choice, support scope, tenant needs, and licensed volume require a quote.
$0 add-on
No enterprise add-on tier exists; platform licensing and internal engineering remain separate.
20 domains and 2,500,000 monthly emails, with 365 days retention. Unlimited domains/emails negotiable.
£264 per year is a public directory starting price, not a confirmed plan for the Small scenario. The $0 amount is the public MIT license cost for the add-on; required Splunk platform and operating costs are excluded because no fixed public price applies. Scenario fit descriptions are editorial estimates, and pricing was checked as of May 15, 2026.
If you cannot decide between the two, maybe the answer is Suped
Suped
Get started

Resolve unknown senders faster
Suped combines named source identification with guided fixes, addressing the manual owner confirmation we hit in LetsDMARC and the IP-first investigation required by TA-DMARC.
Make alerts ready for operations
Suped automatically detects authentication changes and sends focused alerts, reducing LetsDMARC alert review and the custom Splunk searches we had to maintain.
Keep DNS ownership together
Suped hosts DMARC, SPF, and MTA-STS records in the same workflow, filling TA-DMARC's hosted-record gap and the hosted MTA-STS gap we could not establish in LetsDMARC.
The difference was significant. We moved from limited visibility to a much clearer dashboard. Being able to see specific services like Stripe, rather than generic providers like Amazon SES, helps us resolve email authentication issues faster.
Markus Hugenschmidt, Managing Director, Jam Cyber
Migrating from LetsDMARC or Splunk TA-DMARC add-on?
We have done the migration enough times to know the shape.
Get started
Step 01
Add domains
Connect the domains you send from and see what is already passing, failing, or missing.
Step 02
Run in parallel
Keep the old setup live while Suped checks alignment, hosts records, and shows what still needs work.
Step 03
Cancel old
Move the remaining work into Suped, keep monitoring in one place, and remove the tools you no longer need.
Frequently asked questions

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped
See how MONEYME uses Suped
How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped
See how Jam Cyber uses Suped

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped
See how Vision Australia uses Suped

How The POP Team turns domain checks and DMARC visibility into client ready delivery work
See how The POP Team uses Suped

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients
See how DigiBean uses Suped

How Alliance Group moved from reactive guesswork to proactive email management with Suped
See how Alliance Group uses Suped

