DMARC report analyzer

Drop in a DMARC aggregate report (.xml, .gz or .zip) and see every sending source, message count and SPF, DKIM and DMARC result. Runs in your browser.

Analyze DMARC reports

Drop report files here (.xml, .gz or .zip, several at once)

A DMARC aggregate report is an XML file that a mailbox provider such as Gmail or Outlook sends once a day to the rua address in your DMARC record. It lists every IP address that sent mail using your domain, how many messages each sent, and whether they passed SPF, DKIM and DMARC. This analyzer reads those files (zipped, gzipped or plain XML) and turns them into a table of sources, entirely in your browser.

How to read the results

ColumnWhat it means
Source IPThe server that delivered the message to the receiver. Look it up to see which company runs it.
From domainThe domain in the visible From address (header_from). This is the domain DMARC protects.
DMARCPasses when SPF or DKIM passes and is aligned with the From domain. One is enough.
SPF alignedSPF passed for a Return-Path domain that matches the From domain. A pass for the sender’s own bounce domain shows up in Auth results, not here.
DKIM alignedA valid DKIM signature from a domain that matches the From domain.
DispositionWhat the receiver did: none (delivered normally), quarantine (spam folder) or reject.
Auth resultsThe raw SPF and DKIM checks, with the domains and DKIM selectors they were checked against.

What failing sources usually are

  • Your own service, not set up yet. The IP belongs to a platform you use (a CRM, help desk, newsletter tool), SPF or DKIM passes for its domain, but nothing aligns with yours. Turn on DKIM with your domain in that service.
  • Forwarding. SPF fails because a forwarder relayed the mail, but DKIM usually survives and still passes. These rows are normally fine.
  • Spoofing. Unknown IPs with no DKIM and failing SPF are someone else sending as your domain. That’s what p=quarantine and p=reject stop.

DMARC aggregate reports explained goes through every field in the XML, and why DMARC fails covers the fixes. To see a domain’s current records, use the DMARC checker.

Frequently asked questions

Are my DMARC report files uploaded anywhere?

No. The page unpacks and parses them with your browser’s own zip and XML support. You can disconnect from the internet after the page loads and it still works.

Why do I get so many DMARC report files?

Each receiver that got mail from your domain sends its own report, usually once a day. A domain that sends to Gmail, Outlook, Yahoo and a few corporate mail systems gets several files a day.

Why does a source pass SPF but fail DMARC?

SPF passed for the envelope sender (Return-Path) domain, which belongs to the sending service rather than you, so it isn’t aligned with your From domain. DKIM signed with your domain fixes it.

Can this read forensic (ruf) reports?

No. Forensic reports are individual failure messages in a different format. This tool reads aggregate (rua) reports, the XML files defined in RFC 7489.

What if a report won’t open?

The tool shows the reason: not XML, not a DMARC report, or a corrupt archive. Some mail clients save attachments with the wrong extension; that’s fine, because the file type is detected from its contents.