Case study · 2023 — 2025

Inside the EasyDMARC platform.

Designing in-depth, multi-state product surfaces inside a security platform — Aggregate Reports GeoMaps, Reputation Monitoring, User Access Management, the Marketing Materials library, and the MSP integrations flow. Each shipped end-to-end on the EasyDMARC design system.

EasyDMARC product UI — the Aggregate Reports compliance view: an email-volume-by-DMARC-compliance chart with a Sending Sources breakdown (Gmail, Yandex, Zoho, SendGrid, Amazon), a stacked weekly volume chart, and a per-source SPF/DKIM authentication table.
Role
Product Designer
Years
2023 — 2025
Status
Shipped to production
Context

A security platform that needed to feel like a product, not a console.

EasyDMARC helps organizations protect their email — DMARC, SPF, DKIM, BIMI, reputation monitoring, and more. The category tends to live in dense, table-heavy admin consoles built for specialists. Across my time at EasyDMARC I designed a series of tools inside the main app whose job was the opposite: take serious, technical workflows and turn them into clear, navigable, modern product surfaces.

This case study collects four of those tools. Each one is shipped and live in the EasyDMARC platform today. Each one was mine end-to-end — the UX flow, the polished UI, the empty and error states, the modals and drawers, and the visual language they all share with the rest of the system.

The throughline: in security tooling, the difference between “I can find the answer” and “I'm staring at a wall of data” is almost always design. These tools are how I worked that throughline into a real product.

Scope

End-to-end ownership.

Each of the designs below was my sole design responsibility — I owned the flow, the screens, the components, the empty/error/success states, and the modal and drawer patterns. All sit on the EasyDMARC design system, so anything new — a country tooltip, a domain tree, a permission selector, a folder grid, an integration wizard — extended that system rather than fighting it.

  • Aggregate Reports · GeoMaps — a global, country-by-country view of where an organization's email traffic comes from, with three map modes and a layered tooltip system.
  • Reputation Monitoring — an IP and domain reputation tool with a three-step onboarding drawer, a managed/trial dual model, blacklist visibility, and a full set of error and edge states.
  • User Access Management — a permissions surface that supports organization-, product-, domain-group-, and domain-level access, plus bulk operations and a single-pass invite flow.
  • Marketing Materials library — an in-app asset library for MSPs (Managed Service Providers) — folders, drilldowns, list/grid switching, search, and multi-select downloads.
  • Integrations — connecting EasyDMARC to MSP PSA/RMM platforms (HaloPSA, ConnectWise, Acronis, Pax8) through an integrations catalog and a four-step configuration wizard with customer and alert-to-ticket mapping.

A note on the screens below: these are a selection of screenshots from each tool — enough to show the structure and the key states — not the full flow.

Aggregate Reports GeoMaps

Where your email is actually coming from, on a map.

DMARC aggregate reports are powerful but unforgiving — they arrive as XML, organized by sending source and IP. GeoMaps takes that same dataset and answers the question security teams actually ask: which countries is our email coming from, and is it compliant?

I designed three view modes — Filled Map, Point Map, and a Combined View that overlays both — plus a tooltip system that progressively reveals depth as the user hovers from a legend chip to a country to a sending category.

The two views

GeoMaps — Point Map view. The same global dataset shown as clustered circular markers in compliance-coded colors — green for Compliant, orange for Non-Compliant, red for Threat/Unknown, purple for Forwarded — each labeled with its volume.
GeoMaps — Combined View. The Filled Map overlaid with category markers, plus a tooltip on the Compliant legend chip explaining what classifies an email as compliant under DMARC.

Two view modes for the same dataset — Filled Map (volume by country), Point Map (clustered category markers), and a Combined View that overlays both. Each one answers a different question.

Tooltip depth

GeoMaps — a country-level tooltip showing volume, IP addresses, and sending sources, with a compliance breakdown.
GeoMaps — a Point Map cluster tooltip showing the breakdown of the cluster's markers and what each one represents.
GeoMaps — a legend tooltip explaining what 'Non-Compliant' means and which DMARC policies apply.
GeoMaps — a Threat / Unknown legend tooltip with the category definition and the DMARC policy implications.
GeoMaps — a Forwarded legend tooltip explaining how forwarded mail is detected and counted.
GeoMaps — supporting data panels (Top Countries, Top Sending Sources) updating in response to filters.

A tooltip system layered to the data — chip → country → cluster — so users can learn the model without leaving the map.

Empty & activation state

GeoMaps — Top Countries and Top Sending Sources panels in isolation, showing the supporting data the map sits on top of.

The first-run state and the supporting data panels — designed so a new account sees a useful page before the first reports arrive, not an empty map.

Reputation Monitoring

From “is my domain blacklisted?” to a managed workflow.

Reputation Monitoring tracks an organization's IP and domain reputation across a long list of blacklists, and surfaces what's listed where. The challenge: it has to work for an MSP managing dozens of domains across multiple organizations and for a single admin who just wants to check one domain right now.

I designed the empty/activation state, the Managed Domains tree, a parallel Trial Domains tab for accounts evaluating the tool, the three-step Add Domain drawer with inline DMARC verification, all error and skip-verify states, and the small modals that orbit the table (custom name, remove, manage).

Activation

Reputation Monitoring — first-run blocking screen with a clear value statement and two CTAs (Contact Us, Learn More), illustrated with a preview of the tool the user will land in.

First-run state — a value statement, a preview of the tool, and one clear next step. No empty table.

Managed Domains & Trial Domains

Reputation Monitoring — Managed Domains tab. A grouped table showing Domain Group 1, 2, 3 with blacklist counts and date added per domain, plus an information banner about how to remove a domain from a blacklist.
Reputation Monitoring — Managed Domains with a Domain Group expanded, showing per-domain blacklist counts and an indented sub-table of PTR records and their source IPs.
Reputation Monitoring — Trial Domains tab. A table of domains added for evaluation, each with a Trial Time Left column counting down from 30 days, a Custom Name field, and a per-row action menu.
Reputation Monitoring — Trial Domains with a row expanded, showing the PTR / Source IP sub-table for the selected domain, with blacklist status badges per source IP.
Reputation Monitoring — Trial Domains with a per-row action menu open, showing 'Add to Organization', 'Change Custom Name', and 'Remove'.
Reputation Monitoring — Trial Domains with a notice banner explaining the 30-day trial monitoring and what happens when it expires.

The Managed and Trial Domains tabs share the same table grammar — domain, blacklist count, date added, action — so the move from evaluation to production never asks the user to re-learn the screen.

Add Domain — three-step drawer

Add Domain — Step 1, configuration. A right-edge drawer for entering one or many domains, with helper text and validation.
Add Domain — Step 2, management and verification. DMARC record verification with a Quick Guide block explaining what to add to DNS.
Add Domain — Step 3, final verification. A confirmation state showing successful verification and what monitoring will now run.

The three-step Add Domain drawer — Configuration → Management & Verification → Final Verify. Designed as one continuous surface, not three modals.

Skip-verify, error, and modal states

Add Domain — Step 3, skip verify state. The drawer shown when a user defers DMARC verification, with clear messaging about what's monitored anyway.
Add Domain — error case. The drawer with inline validation errors for invalid or duplicate domain entries, showing where each issue lives.
Reputation Monitoring — Change Domain Custom Name modal, with a single input for renaming a trial domain.
Reputation Monitoring — Remove Domain confirmation modal, with Yes/Keep destructive-action pattern.
Reputation Monitoring — managed-domain row action menu, with a contextual Remove option.
Reputation Monitoring — Add Trial Domains entry point and modal.
Reputation Monitoring — Add Domains modal for adding multiple managed domains in one pass.

The states that make the tool feel finished — skip-verify, validation errors, custom-name and remove modals, and the action menus that handle the rare-but-needed paths.

User Access Management

Permissions that scale from one domain to a whole MSP.

EasyDMARC's customers range from a single admin running one domain to MSPs managing hundreds across many organizations. User Access Management is the surface that has to make that range workable: Organization-, Product-, Domain-Group-, and Domain-level access, multiple roles (Admin, Editor, Viewer), and access to one or both products (EasyDMARC, EasySender) — without becoming a permissions maze.

The Users table

User Access Management — the Users table. Columns for User, Level of Access, Role, Products, Last Activity, and Access Status, with avatars and per-row action affordances.
User Access Management — the Users table in a populated state, with active, pending, and inactive users visible at once.
User Access Management — hover state on an active user row, surfacing the row's action affordances.
User Access Management — hover state on a pending user row, with the resend-invite action surfaced.
User Access Management — hover state on an inactive user row, with re-activate action surfaced.
User Access Management — the Users table with a filter chip applied, narrowing the list to one role.

The Users table — one surface that handles active, pending, and inactive users without forcing the admin into three different screens.

Manage Access — drawer at every level

Manage Access drawer — initial state for a user, with Email, Level of Access, Role, and Select Groups fields, plus a destructive Revoke Access link at the bottom-left.
Manage Access drawer — Level of Access set to Organization, Role set to Admin.
Manage Access drawer — Level of Access set to Product, with a Select Products multi-select revealed.
Manage Access drawer — Level of Access set to Domain Group, with a Select Groups multi-select revealed and groups checked.
Manage Access drawer — Level of Access set to Domain, with a Select Domains multi-select dropdown open.
Manage Access drawer — Select Domains multi-select expanded, grouped by domain group, with several domains checked and a '3 out of 900 domains' counter.
Manage Permissions drawer — per-feature permission toggles for the EasyDMARC product.
Manage Permissions drawer — toggles grouped by category with mixed enabled/disabled states.

One drawer pattern, four access levels. The form re-shapes around the level — Domain pulls in a domain multi-select, Domain Group pulls in groups — so the user only sees fields that matter to the choice they just made.

Invite, bulk, and revoke

Invite New User modal — multi-email input with chips, Level of Access, Role, and Select Domains fields.
Invite New User modal — alternate state with a different Level of Access selected, the form re-shaped to match.
Invite New User modal — Role dropdown open, showing Admin / Editor / Viewer options with role descriptions.
Invite New User modal — Select Domains dropdown open, grouped by domain group with checkboxes.
Invite New User modal — review state before sending, with a clear summary of who is being invited at what access level.
User Access Management — bulk operation. Three users selected, with a Manage Access / Revoke Access action bar at the top and a 'Revoke access to Organization' confirmation modal showing the selected users as chips.
User Access Management — 'Access successfully revoked' toast notification with the affected user's name.
User Access Management — Advanced Filter builder, with multiple condition chips combining Level of Access, Role, Products, and Status.
User Access Management — Filter dropdown open over the Users table, with predefined filters and a 'New filter' entry.
User Access Management — filter chips applied, with the table narrowed to a specific access level and role.
User Access Management — combined view with a manage-access drawer open over the filtered Users table.

Invite, bulk-manage, revoke, and filter — the same access logic, expressed in the surface that fits the task. A single-user invite uses a modal; bulk operations promote into an action bar above the table; revoke uses the same destructive-confirmation pattern wherever it appears.

Marketing Materials library
Concept · not yet released

An asset library for MSPs, built into the product.

This tool was designed as a concept and hasn't shipped to production yet.

EasyDMARC's MSP customers resell the platform under their own brand. They need EasyDMARC's marketing materials — logos, illustrations, email templates, white papers — packaged in a way they can actually use. Marketing Materials is the in-app library that gives them that.

I designed the folder grid, the breadcrumb-driven drilldown, the dual list/grid view, the multi-select download flow, and the row-level affordances for downloading folders or individual files.

Folders, drilldown, and view modes

Marketing Materials — root folder grid. Folder cards labeled Logotypes, Backgrounds, Illustrations, Icons, with a Download tooltip on a folder's icon button.
Marketing Materials — drilled into the Logotypes folder. Asset cards showing transparent, white-background, gradient, and blue-background variants of the EasyDMARC mark, plus a nested 'Some random folder'.
Marketing Materials — Logotypes folder with two assets selected, a 'Download Selected Items' action and 'Cancel selection' link visible in the header.
Marketing Materials — list view of the root folder, with columns for Folder Name, Files count, and Folder Size.
Marketing Materials — Logotypes folder list view, with columns for File Name, File Format, and File Size, plus per-row selection checkboxes.
Marketing Materials — list view with two files selected and a 'Download Selected Items' action bar at the top of the table.
Marketing Materials — Logotypes folder in list view, paginated across 97 entries, with two assets selected and the 'Download Selected Items' / 'Cancel selection' controls active in the header.
Marketing Materials — Logotypes drilldown with a 'Download this file' tooltip over a single asset card.

A library that behaves the way file browsers behave — folders, breadcrumbs, list/grid switch, multi-select download — adapted to the EasyDMARC visual language and to MSP workflows.

Integrations

Plugging EasyDMARC into the tools MSPs already run.

MSPs don't live in EasyDMARC all day — they live in their PSA and RMM platforms. The Integrations surface connects EasyDMARC to those tools (HaloPSA, ConnectWise, Acronis, Pax8) so domain data, subscriptions, and alerts flow into the systems an MSP already bills and ticket-handles from.

I designed the integrations catalog, the per-integration detail page, and the four-step configuration wizard — Connect → Subscriptions → Customers → Alerts & Tickets — including the customer-mapping table and the alert-to-ticket mapping that turns an EasyDMARC alert into a PSA ticket.

Catalog & detail

Integrations catalog — a grid of integration cards (Acronis, ConnectWise, Pax8, HaloPSA) each with a Connected / Not Connected status pill and a 'View details' link.

The catalog — every available integration as a card, with connection status at a glance and one way in.

HaloPSA integration detail page — a 'Not Configured' status with a Complete Configuration button, a description of what the integration does (domain mapping, ticket creation, DNS-change and authentication-failure alerts), a product preview, and a Benefits list.

The per-integration detail page — what it does, what it needs, and the single primary action: complete the configuration.

The four-step setup wizard

Integration setup — Step 1, Connect. A stepper (Connect, Subscriptions, Customers, Alerts and Tickets) beside a form for the HaloPSA URL, Client ID, and Client Secret, with a 'HaloPSA Connected' success toast.
Integration setup — Step 2, Subscriptions. Configuring how subscriptions are named in HaloPSA — domain name vs. a custom name — with an Include Domain Names toggle.
Integration setup — Step 3, Customers Mapping. A table mapping EasyDMARC Domain Groups to HaloPSA Customers, with a Filter Customers popover (Relationship, Type, Account Status) open.
Integration setup — Step 4, Alerts and Tickets. An alerts-group mapping table (DMARC record change, SPF Validation failed) with per-alert Mapped toggles, and per-customer ticket settings (Category, Impact, Urgency, Site) with a ticket-type dropdown open.

One stepper, four jobs — connect the account, decide how subscriptions are named, map domain groups to PSA customers, then map each alert type to the ticket it should open. The same stepper, drawer, table, and popover patterns from the other four tools, reused here.

Outcome

One shared vocabulary across every tool.

Most of these tools shipped and are in production in the EasyDMARC platform today, while the Marketing Materials library was designed as a concept and hasn't released yet. More importantly, the patterns I designed for each one — the right-edge configuration drawer, the destructive-confirmation modal, the empty/activation state with a preview of the tool, the level-aware permission form — became patterns the rest of the platform could reach for.

That's the part of this work I'm most proud of. Each tool is a finished surface; together, they're a small case study in how a security platform stops feeling like a console.

What I'd take into the next one

The most useful working pattern from these projects was thinking in levels before screens. User Access Management has four access levels; Reputation Monitoring has Managed and Trial; GeoMaps has three view modes; the library has folder and file; Integrations has four setup steps. In each case, the structure of the tool came out of the level model — not out of trying to fit one screen around every case. When the levels are right, the screens almost design themselves.

Happy to walk through any of them in detail — flow choices, tradeoffs, the states that didn't make the cut — in a conversation.

Get in touch

Like what you see?

I'm open to senior product design roles and select freelance engagements. Always happy to chat.

Get in touch