Skip to content
Free, nothing stored

DMARC report analyser

Upload one DMARC aggregate report, as it arrived, and see which servers sent email as the domain, how much, and whether it passed SPF, DKIM and DMARC.

Upload a report

Up to 900 KB. Reports arrive zipped or gzipped; upload the attachment as it is.

The report is read in memory and thrown away. We don't store it, its contents or its name, and nothing from it is logged.

Reading a DMARC aggregate report

Mailbox providers such as Google, Microsoft and Yahoo send a daily aggregate report to the address in a domain's DMARC rua= tag. Each report covers one day of email that receiver saw claiming to be from the domain: the sending server's IP address, how many messages it sent, and how each one fared.

What the columns mean

  • DMARC: passes when SPF or DKIM passed and lined up with the From domain. This is what the policy acts on.
  • SPF and DKIM: the raw result, then whether it was aligned. A pass that isn't aligned (a service authenticating as its own domain) doesn't count for DMARC.
  • Receivers did: what happened to the email: delivered (none), sent to spam (quarantine) or refused (reject). Receivers may override the policy, for example for forwarded mail.

What to do with it

Sort the failing sources into two piles. Services you use (a CRM, a newsletter tool, a help desk) need SPF or DKIM set up for the domain; their help pages explain how. Anything you don't recognise is someone else sending as the domain, which is what p=quarantine and p=reject stop. Once every real service passes, tighten the policy. The guide What is DMARC? walks through each step.

One report is a snapshot from one receiver. To see the whole picture, reports need reading every day, from every receiver, for every domain: that's the job Domain Health Hub does, alongside the DMARC record check.

Do this for every client, every day

  • All nine checks on every client domain, daily, graded A to F
  • Alerts by email or webhook when a grade drops or a record changes
  • A monthly report card for each client, with your logo on it
  • Hosted DMARC, SPF, DKIM and MTA-STS, so fixes don't wait for a DNS login

Start a free 28-day trial: up to 3 domains, no card needed.

Questions

Do you keep the report I upload?

No. It's unpacked and read in memory, the summary is sent back to your browser, and the file is thrown away. Nothing from it is stored or logged.

Which files can I upload?

One DMARC aggregate report as XML, or the .gz or .zip attachment it arrived in, up to 900 KB. If a zip holds several reports, the first is shown.

Why are there no server names, only IP addresses?

Reports only contain IP addresses. Domain Health Hub's app looks up the reverse DNS name of each sending server so you can tell services apart.

Can it read forensic (ruf) reports?

No, and we don't accept them anywhere. Forensic reports can contain personal data from individual emails; aggregate reports are what you need.

Why does a source pass SPF but fail DMARC?

SPF passed for the service's own domain (its Return-Path), not yours, so it isn't aligned. Set up DKIM signing with your domain at that service, or a custom Return-Path.

Let us read every DMARC report for you.

Start a free 28-day trial: up to 3 domains, no card needed.