Drop in the XML, gzip or zip files your DMARC reports arrive as and read what they actually say: how much of your mail passes, which sources fail, and which failures are a platform to configure rather than someone to block. Parsed in your browser; nothing is uploaded.
Once your DMARC record has a rua address, every major mailbox provider sends a daily XML file listing each IP that sent mail as your domain, how many messages it sent, whether SPF and DKIM passed, whether either aligned with the From domain, and what the receiver did. It is the only view you get of who is sending in your name.
Two columns trip people up. policy_evaluated says whether an aligned identifier passed, which is what DMARC acts on. auth_results says whether SPF or DKIM passed at all, for whatever domain. SPF "pass" in one and "fail" in the other is not a contradiction: it is a platform sending with its own return path. This analyzer keeps them apart and sums message counts, never rows.
Authenticated and aligned. Nothing to do.
A service passes SPF or DKIM for its own domain. Configure it to sign as yours; editing SPF will not help.
Nothing passes. Either a service you forgot to set up, or someone spoofing you, which enforcement stops.
Usually forwarding or mailing lists breaking SPF, or one unsigned stream from a shared server.
The biggest sources are named by their PTR hostname, so you can recognise Google, Microsoft or your email platform.
Reads RFC 7489 reports and the DMARCbis format, in plain XML, .xml.gz or .zip.
When nearly all mail (98% or more) passes and every failing source left is one you do not recognise. A high pass rate alone is not enough: a low-volume system you forgot, like invoicing, can still fail.
The source passed SPF for its own envelope domain, which is not your domain, so it does not align. Set up DKIM signing as your domain, or a custom return path, for that service.
Forwarding usually breaks SPF and sometimes DKIM. Receivers often apply local policy overrides for known forwarders; those show up as a forwarded or mailing-list reason.
No. Files are decompressed and parsed in your browser. Only the reverse-DNS names of source IPs are looked up.
Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.
Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.
Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.
Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.
See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.