Skip to main content

Senders List

The Senders List page gives you full control over the email sources detected for a domain through DMARC reports. Access it from the gear menu on the Domain Overview page.

note

The Senders List is only available for domains that have DMARC monitoring set up and are receiving DMARC reports.

How It Works

As Palisade processes DMARC aggregate reports, it identifies email sources (sending services and IPs) that are sending mail on behalf of your domain. Each source is categorized into one of three statuses.

Pending Sources

Sources that have been detected but not yet reviewed. Each pending source shows:

  • Source name — the identified sending service or IP
  • 14-day email compliance — pass/fail rates over the last two weeks

For each pending source, you can:

  • Confirm — mark the source as a legitimate, authorized sender
  • Discard — mark the source as unauthorized or irrelevant

Confirmed Sources

Sources you have confirmed as legitimate senders. These are recognized as authorized and factor into compliance calculations.

Each confirmed source also shows when Palisade last saw mail from it:

  • Last seen today, Last seen 4 days ago, Last seen 3 months ago — the most recent day this source appeared in a DMARC report for your domain. It is always written as a distance rather than a date, and always rounded down, so it never overstates how long a sender has been quiet.
  • Not seen sending — no report has ever carried mail from this source.

Once a source has been quiet for the full activity window, the same line is highlighted as a warning. It still reads as an observed date you can check, not as an instruction.

The Activity Window

The activity window is 90 days. It is the same 90 days the DMARC Agent waits before raising a ticket, so a sender flagged on this page and a sender flagged in your ticket queue always mean the same thing.

This page only ever reports a day something was observed, which is a fact whatever the coverage. A claim about the absence of mail is not, and it is only worth anything if Palisade was watching for the whole period. So before Hosted SPF shows its "No mail in 90 days" chip, or the DMARC Agent raises a ticket, Palisade checks the first day it received a DMARC report for the domain. On a domain monitored for less than the window the silence is Palisade's rather than the sender's, and neither claim is made.

Last seen also appears per SPF entry on Hosted SPF, and per sending service on Hosted DKIM. When a confirmed sender stays silent for the full window on a domain that was monitored throughout it, the DMARC Agent opens a Confirmed sender has stopped sending ticket.

Discarded Sources

Sources you have marked as unauthorized or irrelevant. Discarded sources are hidden from the main view but can be reviewed and restored if needed.

Why Manage Senders

Reviewing and confirming senders helps you:

  • Identify all legitimate services sending email for your domain
  • Spot unauthorized senders before tightening your DMARC policy
  • Build confidence that moving to quarantine or reject will not block legitimate mail
  • Track which services need SPF or DKIM configuration updates
Review senders before enforcement

This page is a critical stop before tightening your DMARC policy. Any legitimate sending service that is not properly authenticated (passing SPF or DKIM) will have its mail quarantined or rejected once enforcement is active. Review pending sources carefully — a service you do not recognize may still be legitimate (e.g., a CRM, helpdesk, or marketing tool set up by another team).

tip

New senders can appear at any time — for example, when a colleague sets up a new email tool. Check back periodically, especially after organizational changes, to catch new sources before they become a delivery problem.