DomainCanary Start free

Guides

35,050 domains list a DMARC report address without authorization

Last updated 11 Oct 2026

Your DMARC record can list a reporting address on someone else's domain. Receivers that follow the standard send reports there only when that domain's owner has published a record to authorize it. In our October 2026 scan, 35,050 domains listed an outside address whose owner hadn't.

Is my DMARC record one of them? Run our DMARC checker. It looks up the authorization record for every outside address in your rua= tag.

  1. Find your reporting addresses. Run dig +short TXT _dmarc.yourdomain.example and read the rua= tag.
  2. Check each address on another domain. For dmarc@reports.example.net, run dig +short TXT yourdomain.example._report._dmarc.reports.example.net. No answer starting with v=DMARC1 means receivers that check won't send reports there.
  3. Authorize an address you own. If the other domain is yours, publish the record below in that domain's DNS.
  4. Replace an address you don't own. If a platform added it or you copied it from a guide, swap it for an address you can read. Leave p= and every other tag as they are.
yourdomain.example._report._dmarc.reports.example.net. TXT "v=DMARC1;"

Receivers that follow the standard check the address first

Before a receiver sends an aggregate report to an address outside your domain, it should look for a TXT record at yourdomain.example._report._dmarc.<address domain>. If the record isn't there, the receiver drops the report. You get no error and no bounce, so you won't know the reports have stopped.

The rule is in RFC 7489, section 7.1, and RFC 9990, section 4 keeps it. Google's DMARC report help and Microsoft's cross-domain reporting docs both say you need the record.

Not every receiver enforces it. Ashiq and others (USENIX Security 2023) found that Google sent reports without the record in their tests. A domain without the record can still get some reports, but it can't count on any of them.

Gmail inboxes and platform templates lead the list

The table lists the outside addresses we could trace to a platform, a mailbox provider or a setup guide. The first count is every domain whose record lists the address. The second is the domains whose record lists only outside addresses without authorization, so they have no authorized address to fall back on.

Address hostDomainsNo authorized
address
gmail.com2,4502,159
qq.com858839
smtp.mailtrap.live353311
reporting.unisender.com282276
fbl.optin.com249212
smtp-staging.mailtrap.net176153
lovable.dev138107
yourdomain.com104102
example.com9282

The rest of the 35,050 domains list addresses at other hosts. Across all of them, 30,229 list only outside addresses without authorization, so receivers that check have nowhere to send their reports.

We emailed Mailtrap and Lovable on 2 Oct 2026 to ask whether their setups add these addresses. As of 11 Oct, neither has replied or published the missing records.

Mailtrap shows both of its addresses in its setup guide

The screenshots in Mailtrap's sending-domain setup guide show a DMARC record with smtp.mailtrap.live in it. Another screenshot in the same guide shows smtp-staging.mailtrap.net.

Unisender's address is the same on every domain

Every domain with a reporting.unisender.com address lists the same one, dmarc@reporting.unisender.com. Unisender is an email marketing service.

optin.com's wildcard answers only one label deep

optin.com publishes a wildcard authorization record at *._report._dmarc.fbl.optin.com. Its nameservers answer it for a made-up name one label deep. A real domain name has at least two labels, and the lookup for one comes back as a name that doesn't exist.

Lovable's docs mention a DMARC record but not this address

Lovable's custom email docs say its setup adds a DMARC record when you turn on "Show as sent from @yourdomain.com". The docs don't print the record, and Lovable hasn't confirmed it adds the lovable.dev address.

Personal Gmail and QQ Mail inboxes have no authorization

An address at gmail.com or qq.com is someone's personal inbox. Google and Tencent publish no authorization records for their users' addresses, so receivers that check won't send reports there.

Placeholders copied from setup guides

yourdomain.com and example.com are the placeholder names that sample records use. Someone else registered yourdomain.com, and it publishes no authorization records. example.com is reserved for documentation and accepts no mail.

Platforms that add an address can fix it once

If your platform puts its own address in customers' DMARC records, publish a wildcard authorization record for that address's domain. Then look up a real customer domain under it, such as customer.example._report._dmarc.reports.example.net. A domain name has at least two labels, and some DNS servers answer a wildcard only one label deep.

*._report._dmarc.reports.example.net. TXT "v=DMARC1;"

If you don't read those reports, stop adding the address, and show customers how to add their own. Leave any address a customer has already added.

How we counted

The numbers come from the October 2026 DMARC Census, our monthly scan of the Tranco top million and the US federal .gov list. For every outside rua= address, the scan looked up the authorization record the way a receiver does.

We counted a failed lookup as unknown. The counts for each host are in the edition's data file, aggregates.json, under CC BY 4.0.

Some of the domains in the table publish p=quarantine or p=reject. Some also list a second address on their own domain or with authorization, and those are in the first count but not the second.

We checked each host in the table by hand, through Cloudflare's and Google's public resolvers and the host's own nameservers, including a probe for a wildcard record. The scan reads DNS, so it can't see whether anyone reads the reports that do arrive.

Get reports at an address that works

DomainCanary gives you a reporting address on our own domain, and we publish the authorization record for every domain that uses it. We read the reports from every receiver and show each server that sent as your domain. Your first domain is free.

Read your domain's DMARC record

The policy, the alignment modes and where the reports go, with the gaps marked.

Free · No signup · The result names what to change

Questions

What is a DMARC report authorization record?

A TXT record that lets one domain receive DMARC reports for another. When your rua address is on a different domain, receivers that follow the standard look up a name such as yourdomain.example._report._dmarc.reports.example.net and send reports there only if it returns v=DMARC1. RFC 7489 section 7.1 defines it, and RFC 9990 section 4 keeps it.

Do Gmail and Outlook check for the authorization record?

Google's and Microsoft's help pages both say the record is required. A 2023 study by Ashiq and others at USENIX Security found that Google sent reports without it in their tests. A domain without the record can still get some reports, but it can't count on any of them.

How do I let another domain I own receive my DMARC reports?

Publish a TXT record with the value v=DMARC1; at yourdomain.example._report._dmarc.otherdomain.example, in the DNS of the domain that receives the reports.

DomainCanary is a DMARC enforcement service that protects your domain from email spoofing without blocking your own mail.