DMARC report analyzer
Drop in a DMARC aggregate report (.xml, .gz or .zip) and see every sending source, message count and SPF, DKIM and DMARC result. Runs in your browser.
Analyze DMARC reports
Drop report files here (.xml, .gz or .zip, several at once)
A DMARC aggregate report is an XML file that a mailbox provider such as Gmail or Outlook sends once a day to the rua address in your DMARC record. It lists every IP address that sent mail using your domain, how many messages each sent, and whether they passed SPF, DKIM and DMARC. This analyzer reads those files (zipped, gzipped or plain XML) and turns them into a table of sources, entirely in your browser.
How to read the results
| Column | What it means |
|---|---|
| Source IP | The server that delivered the message to the receiver. Look it up to see which company runs it. |
| From domain | The domain in the visible From address (header_from). This is the domain DMARC protects. |
| DMARC | Passes when SPF or DKIM passes and is aligned with the From domain. One is enough. |
| SPF aligned | SPF passed for a Return-Path domain that matches the From domain. A pass for the sender’s own bounce domain shows up in Auth results, not here. |
| DKIM aligned | A valid DKIM signature from a domain that matches the From domain. |
| Disposition | What the receiver did: none (delivered normally), quarantine (spam folder) or reject. |
| Auth results | The raw SPF and DKIM checks, with the domains and DKIM selectors they were checked against. |
What failing sources usually are
- Your own service, not set up yet. The IP belongs to a platform you use (a CRM, help desk, newsletter tool), SPF or DKIM passes for its domain, but nothing aligns with yours. Turn on DKIM with your domain in that service.
- Forwarding. SPF fails because a forwarder relayed the mail, but DKIM usually survives and still passes. These rows are normally fine.
- Spoofing. Unknown IPs with no DKIM and failing SPF are someone else sending as your domain. That’s what
p=quarantineandp=rejectstop.
DMARC aggregate reports explained goes through every field in the XML, and why DMARC fails covers the fixes. To see a domain’s current records, use the DMARC checker.
Frequently asked questions
Are my DMARC report files uploaded anywhere?
No. The page unpacks and parses them with your browser’s own zip and XML support. You can disconnect from the internet after the page loads and it still works.
Why do I get so many DMARC report files?
Each receiver that got mail from your domain sends its own report, usually once a day. A domain that sends to Gmail, Outlook, Yahoo and a few corporate mail systems gets several files a day.
Why does a source pass SPF but fail DMARC?
SPF passed for the envelope sender (Return-Path) domain, which belongs to the sending service rather than you, so it isn’t aligned with your From domain. DKIM signed with your domain fixes it.
Can this read forensic (ruf) reports?
No. Forensic reports are individual failure messages in a different format. This tool reads aggregate (rua) reports, the XML files defined in RFC 7489.
What if a report won’t open?
The tool shows the reason: not XML, not a DMARC report, or a corrupt archive. Some mail clients save attachments with the wrong extension; that’s fine, because the file type is detected from its contents.