DomainCanary Start free

DMARC report analyzer

Turn one DMARC aggregate report into sentences: who sent as your domain, what passed, and what the receiver did about the rest. No account, and nothing is stored.

or

.xml, .xml.gz and .zip, up to 5 MB. Reports arrive as an attachment on mail from the receiver, so this is usually the attachment saved straight out of your mail client.

What a DMARC report analyzer shows you

An aggregate report is an XML file a receiver writes about your domain, usually once a day, and mails to the address in your DMARC record's rua= tag. It holds one row per sending IP: how many messages, whether SPF and DKIM passed and aligned, and what the receiver did with the ones that failed. This page unpacks one file and prints what it says.

Start with the rows that failed DMARC. A source can show spf=pass and still fail if the pass was for the sending platform's domain instead of yours. That's alignment. The DMARC column is the verdict receivers act on.

Then look at the disposition. none means the mail was delivered anyway, quarantine means it went to spam, and reject means it never arrived. A report full of failures under p=none costs you nothing yet. The same report under p=reject is mail that never reached your customers.

Questions

Who sends these reports, and why is the file zipped?

Google, Microsoft, Yahoo and a few hundred smaller receivers, each in its own file. They arrive gzipped or zipped, with a name like google.com!example.com!1754956800!1755043199.zip, and one day of a small domain's mail can run to hundreds of rows. The report carries no subjects, bodies or recipients. It's a tally of who sent as you and how the checks went.

Why does the disposition say none when my policy is quarantine?

The disposition is what the receiver did, and it usually follows the policy it saw. A receiver that recognized the mail as forwarded, or overrode the policy for a reason of its own, says so in the record. That reason is shown beside the disposition.

What do the DKIM selectors tell me?

Which platform a source belongs to. Each platform signs with its own selector, so it's the quickest way to put a name on an IP. Our DKIM checker confirms whether the matching key is still published, and the SPF, DKIM and DMARC checker reads all three of your records at once.

Why is a platform I use missing from this report?

A report covers one day at one receiver. A platform that sends your invoices on the first of the month is absent from every report for the other thirty days. When it does show up failing, read that report the day it arrives, because the next one that names it is a month away.

Can I tighten my policy from one report?

No. The call to move from p=none to p=quarantine comes from weeks of reports, read together, per source. Reading an aggregate report by hand covers the patterns to look for, and the DMARC setup guide covers the ramp up to p=reject.

What happens to the file I upload?

Nothing is stored. The file is parsed in memory to build this page and dropped when the response is sent. It isn't written to disk, logged or attached to an account. If you sign up from the card above, the From domain out of the report is filled into that form, and it reaches us only if you submit it. Reports describe other people's sending setups as well as your own, which is why we don't keep the ones pasted into a public form.

The last report you open by hand

Receivers write a new one every day. Point your rua tag at us and all of them turn into one Monday email: who sent as your domain and what failed. Every plan keeps per-source totals for the life of the account, the free one included. Paid plans email you the day a new sender fails.

Get the weekly digest

Free for your first domain · No card · Per-source totals kept for life

The other tools