Skip to content
DMARC

DMARC reports: no rua address, or reports going elsewhere

Without rua= nobody sees who sends email as the domain. How to add a report address, send reports to two places, and authorise another domain.

By the Domain Health Hub team · Updated

In short
  • rua= is where receivers send daily aggregate reports: which servers sent as the domain, and whether they passed.
  • Without it you can't safely move past p=none, because you can't see what would break.
  • rua= takes several addresses. A reporting service on another domain must authorise itself in its own DNS.

What it means

Either the DMARC record has no rua= tag, so receivers have nowhere to send reports, or the reports go to an address elsewhere and so don't appear in your Domain Health Hub dashboard. The first is a real gap. The second is fine if someone reads them; you can add a second address so both get a copy.

Aggregate reports arrive roughly daily from each large receiver. They list every IP address that sent email using the domain, how many messages, and whether SPF, DKIM and DMARC passed. That's how you find the forgotten newsletter tool before p=reject blocks it.

How to confirm it

How to fix it

Add rua= with one or more addresses, each with mailto:. In Domain Health Hub, each domain's page shows its own report address to copy.

_dmarc.example.com TXT
v=DMARC1; p=none; rua=mailto:dmarc@example.com,mailto:reports@vendor.example

Reports to another domain

If the report address is on a different domain from the one being reported on, section 7.1 of RFC 7489 says receivers must check that the other domain agrees to take them. They look up a TXT record at example.com._report._dmarc.vendor.example (the reported domain, then _report._dmarc, then the report address's domain), which must start v=DMARC1. If it isn't there, that address is skipped.

That record lives in the reporting service's DNS, not yours. A reporting service sets it up on its side; Domain Health Hub publishes one that covers every domain sending reports to its addresses. If you send reports to a mailbox on another domain you own, add the record there yourself.

Cloudflare DNS

  1. Open the domain in the Cloudflare dashboard and go to DNS, then Records.
  2. Add a record of type TXT with the name _dmarc. Cloudflare adds the domain for you.
  3. Paste the record as the content and save.

Microsoft 365

Microsoft 365 doesn't publish DMARC for your own domain: the record goes wherever the domain's DNS is hosted (your registrar, Cloudflare or similar). Only the onmicrosoft.com domain, or a domain whose DNS Microsoft hosts, is managed in the Microsoft 365 admin centre. Turn on DKIM in the Defender portal before you tighten the policy, so Microsoft 365 email passes on DKIM as well as SPF.

Google Workspace

The same applies: add the TXT record at your DNS host. Make sure Gmail is signing with DKIM for your domain first (Admin console, Apps, Google Workspace, Gmail, Authenticate email), or forwarded email will fail DMARC once you move past p=none.

Questions

Do aggregate reports contain personal data?

Very little: sending IP addresses, counts and pass or fail results, with no message content. They are not the same as forensic (ruf) reports.

Can I send reports to two services?

Yes. List both after rua=, separated by a comma, each with mailto: in front.

Hear about it the day it breaks.

Daily checks on every client domain, alerts when something changes, and a monthly report card your clients will understand.

Start 28-day free trial