DMARC report analyzer

Drop in the XML, gzip or zip files your DMARC reports arrive as and read what they actually say: how much of your mail passes, which sources fail, and which failures are a platform to configure rather than someone to block. Parsed in your browser; nothing is uploaded.

Drop DMARC aggregate reports here .xml, .xml.gz or .zip, as many as you have · read in this browser, never uploaded

…or instead · .

One report covers one receiver for one day. Load a week or two from your biggest receivers before drawing conclusions.

How it works

Turning daily XML into decisions

Once your DMARC record has a rua address, every major mailbox provider sends a daily XML file listing each IP that sent mail as your domain, how many messages it sent, whether SPF and DKIM passed, whether either aligned with the From domain, and what the receiver did. It is the only view you get of who is sending in your name.

Two columns trip people up. policy_evaluated says whether an aligned identifier passed, which is what DMARC acts on. auth_results says whether SPF or DKIM passed at all, for whatever domain. SPF "pass" in one and "fail" in the other is not a contradiction: it is a platform sending with its own return path. This analyzer keeps them apart and sums message counts, never rows.

Passing

Authenticated and aligned. Nothing to do.

Authenticated, not aligned

A service passes SPF or DKIM for its own domain. Configure it to sign as yours; editing SPF will not help.

Not authenticated

Nothing passes. Either a service you forgot to set up, or someone spoofing you, which enforcement stops.

Partly passing

Usually forwarding or mailing lists breaking SPF, or one unsigned stream from a shared server.

Reverse DNS

The biggest sources are named by their PTR hostname, so you can recognise Google, Microsoft or your email platform.

Both schema revisions

Reads RFC 7489 reports and the DMARCbis format, in plain XML, .xml.gz or .zip.

FAQ

Common questions.

When is it safe to move from p=none to quarantine?

When nearly all mail (98% or more) passes and every failing source left is one you do not recognise. A high pass rate alone is not enough: a low-volume system you forgot, like invoicing, can still fail.

Why does SPF show pass but DMARC fail for a source?

The source passed SPF for its own envelope domain, which is not your domain, so it does not align. Set up DKIM signing as your domain, or a custom return path, for that service.

What about forwarded mail?

Forwarding usually breaks SPF and sometimes DKIM. Receivers often apply local policy overrides for known forwarders; those show up as a forwarded or mailing-list reason.

Are my reports uploaded?

No. Files are decompressed and parsed in your browser. Only the reverse-DNS names of source IPs are looked up.

More free tools

Keep going.

DMARC Checker

Read the DMARC policy, alignment and reporting tags, and check that report addresses will accept reports.

SPF Checker

Validate the SPF record, follow every include, and count DNS lookups against the limit of 10.

DKIM Checker

Find the DKIM public key for a selector (or auto-detect common ones) and check its size and flags.

Email Header Analyzer

Trace a message hop by hop, read the receiver's SPF/DKIM/DMARC verdicts and check DMARC alignment.

Inbox Preview

See how your HTML email actually renders in real Gmail, Outlook.com and Yahoo Mail accounts. Free screenshots.

All email tools