Read a DMARC report in plain words
Drop in the report a receiver emailed you and see who is sending as your domain, how much, and whether it passed. Your report is read in your browser. Only the source IP addresses are sent to us, to name the senders.
Drop a DMARC report here
XML, .gz or .zip, exactly as the receiver emailed it. Read in your browser; only the source IPs are sent to us, to name the senders.
Or paste the XML instead
What is a DMARC aggregate report?
Once your domain has a DMARC record with a rua= address, every large receiver that handles mail claiming to be from you sends that address one summary a day. Google, Microsoft, Yahoo and a long tail of others each send their own. The summary is an XML file, usually attached as a .zip or .xml.gz, and the email it arrives in has a subject like Report domain: halden.co Submitter: google.com.
Inside, the receiver lists each IP address that sent mail with your domain in the From line, how many messages came from it, whether SPF and DKIM passed in alignment with your domain, and what the receiver did as a result. It is not a list of individual emails and it contains no message content, which is why the files are safe to read with a tool like this one.
How do I tell a legitimate sender from a spoofer in the report?
Look at the checked domains column. A newsletter platform or a CRM that sends on your behalf will show its own domain there, for example mcsv.net or amazonses.com, with a passing result for that domain and a failing one for yours. That is a real service that is not yet aligned: it needs DKIM signing with your domain turned on in its settings, or its sending servers added to your SPF record.
A spoofer looks different. The source IP is one you have never heard of, nothing passes for any domain, and the message count is often small and bursty. Under a quarantine or reject policy those messages are already being stopped, which is the point. Searching the IP address in a reverse DNS or WHOIS lookup usually settles it: a hosting provider in a country you do not operate in is not your invoicing tool.
What should I do after reading a report?
If every source passes, you are ready to tighten the policy. Use the DMARC record generator to build the next step and the DMARC checker to confirm it is live. If a service you use is failing, fix it before tightening: with a reject policy that service's mail would start bouncing. If only strangers are failing, your policy is doing its job and nothing needs to change.
Reports arrive from every receiver, every day, so after the first few you will know your sources by their IP ranges. Keep the files; when a new source appears, the old reports tell you whether it is new or just newly noticed.
Faivelo sets up DMARC with reports from day one.
Add your domain and SPF, DKIM and a DMARC record with a report address on your own domain are written into your DNS for you. Business email on your domain from one flat price.
Free 14-day trial. No card needed.
Questions people ask
Other free tools
All tools- Email DNS checkerCheck MX, SPF, DKIM, DMARC and reverse DNS for any domain and get the exact records to add or fix.
- DMARC checkerLook up a domain's DMARC record, read every tag in plain words and see what to tighten next.
- DMARC record generatorBuild a valid DMARC record from a few choices and copy the host and value into your DNS.
- SMTP connection testerConnect to any SMTP server, check TLS and the login step, and see each stage with its timing.
- Email header analyzerPaste raw headers to see every hop, where the delay was, and whether SPF, DKIM and DMARC passed.
- Email address validatorCheck whether an address is well formed, whether its domain accepts mail, and whether it is disposable or a role account.
- SMTP error codesWhat each bounce code means, which provider sends it and how to fix it, one page per code.