Set up DMARC on Namecheap with your AI assistant
Palisade gives your assistant the exact records for the domain, tells it Namecheap is the host answering for that zone, and confirms against live DNS once they are published. You approve every record, and no Namecheap credential ever reaches Palisade.
Adding the DMARC record in Namecheap
The record is one TXT entry at _dmarc. This is the short version of the click path, and it is worth knowing even if you never use it again.
Check which DNS the domain uses
Advanced DNS is authoritative only on BasicDNS, PremiumDNS or FreeDNS. On Namecheap Web Hosting DNS the records are added through cPanel, and on Custom DNS they belong to whichever host the nameservers point at.
Add the TXT record
Open Domain List, choose Manage on the domain, open Advanced DNS, then Add new record. Choose TXT Record and paste the policy into Value.
Put _dmarc in the Host field on its own
Namecheap appends the domain for you, so the Host field takes _dmarc and not _dmarc.yourdomain.com. Typing the full name creates a record at _dmarc.yourdomain.com.yourdomain.com, which nothing queries.
Save all changes, then allow for the delay
Namecheap documents roughly 30 minutes before a saved record takes effect, so a lookup straight afterwards can still return the old answer.
Domain List, Manage, Advanced DNS, Add new record is the path as Namecheap labels it today. Provider dashboards get renamed, so the current official reference is Namecheap: how to add TXT, SPF, DKIM and DMARC records.
The same setup, without the dashboard
Connect Palisade's MCP server to Claude, ChatGPT, Copilot, or any MCP client, and the record values stop being something you transcribe.
Add the domain
Your assistant calls add_domain and the domain starts being monitored. Adding a domain is free and never gated, so a whole portfolio can go in before anything is set up.
Get the exact records
get_dns_records returns each record to publish with its host, type, value, recommended TTL and whether it needs creating, replacing or deleting. It also reports the DNS host resolved from the domain's live nameservers, so your assistant is told this zone is on Namecheap rather than guessing from the registrar.
Publish them where the zone lives
The Palisade MCP server has no tool that writes a record at Namecheap. It hands your assistant the values, and your assistant publishes them with the DNS tooling it already has. In the Palisade app, Smart DNS Deployment is the other route: you authorise the connection in the provider's own window and approve each record, and Palisade writes it into your own zone.
Verify against live DNS
verify_domain re-checks from outside your account, so a record saved into the wrong zone or still inside its TTL shows as unverified rather than done. Setup is finished when every required record verifies.
Connecting takes one step and no API key to create first. The setup for each client is on the Palisade MCP server page.
What Palisade knows about your Namecheap zone
The question worth asking before you connect anything, answered first.
| Namecheap credentials | Never requested, never stored, never seen. Palisade has no field for a Namecheap API token or password. |
|---|---|
| How the provider is identified | From the domain's live NS records. Namecheap is recognised by nameservers under registrar-servers.com, and that lookup is public information about your domain rather than access to your account. Namecheap's own nameservers cover BasicDNS, PremiumDNS and FreeDNS. A domain switched to Custom DNS answers from somewhere else entirely. |
| What the MCP server can change | Nothing in your zone. No tool in the server writes a record at an external provider; it returns the values and your own tooling publishes them. |
| If you want Palisade to publish instead | Smart DNS Deployment, in the Palisade app, covers 64 providers. You authorise the connection in the provider's own window, the access covers email-authentication records only, you approve each record, and you can disconnect at any time. |
| Your registrar and nameservers | Unchanged. Nothing is transferred and Palisade never takes over the zone. |
What publishing to Namecheap looks like
You approve the exact record. The connection is authorised in the provider's own window, and nothing else in the zone is touched.
- Setting up acme-corp.com: its email-authentication records are unconfigured, and instead of setting them up by hand you choose Configure.
- Palisade recognises Namecheap as the provider answering for the domain, and you authorise the connection in Namecheap’s own window. No password is shared with Palisade, and access is scoped to email-authentication records only.
- The exact records are shown as a before-and-after diff: the SPF value gaining a sender, plus new DKIM and DMARC records. Nothing is published until you press Approve and publish.
- Every record is live and verified in your own zone, monitoring stays on, and nothing else in the zone was touched.
Publishing DMARC is the start, not the finish
A published record proves the policy exists. Whether your mail actually authenticates is a question the record UI never answers.
Drift, including the record you just published
A record that is edited, overwritten by another tool, or dropped during a Namecheap change stops matching what Palisade generated. Monitoring keeps checking live DNS after the write, so a change that silently did not take becomes a task instead of something you learn from a bounce weeks later.
Senders that are failing authentication
Aggregate reports name the services sending as your domain and show which of them pass SPF and DKIM with alignment. A new marketing platform someone signed up for without telling you shows up here first.
Remediation as tasks, with the fix already drafted
Palisade opens a task for each failing source and record issue, ordered by priority, and a task can carry provider-specific instructions for the sender involved. The agent investigates every sender, drafts every fix, and proposes each policy step. You approve before anything ships.
Readiness to tighten the policy
Moving from p=none toward quarantine and then reject is safe only once the legitimate senders are accounted for. Palisade tracks when that is true for the domain and proposes the step rather than taking it.
Namecheap DMARC: FAQ
Set up DMARC on Namecheap from the assistant you already use
1 domain free up to 1,000 emails/month
