DMARC Analyzer
Monitor domains and review DMARC aggregate reports.
toolboxdmarcreportsdomains
DMARC Analyzer
The DMARC Analyzer is available when the Workspace has the dmarc_reports feature and your role can read it. It helps review DMARC aggregate reports for monitored domains.
- Create one monitor per domain. Domains are normalized, and monitors can be active or paused.
- Monitors that already have imported reports cannot be deleted; pause them when ingestion should stop.
- Attach an active IMAP mailbox to a monitor when you also have Workspace settings management access. The picker includes Gmail, standard IMAP, and native iCloud mailboxes. When a directly connected mailbox has no individual account scope, Einblick labels it as Workspace-wide before selection. Active monitors use the chosen mailbox to ingest matching DMARC report attachments automatically.
- Upload aggregate report files manually as XML, ZIP, GZIP, or
.xml.gz. Raw uploads are capped at 25 MB. - ZIP uploads can contain up to 25 XML reports. Each XML report is capped at 5 MB after decompression, and one import can contain up to 5,000 aggregate rows.
- Raw uploaded files are stored in the system
DMARC Reportsfolder in Files. - Duplicate aggregate reports are detected by fingerprint and marked as duplicate instead of being imported again.
- The dashboard shows total volume, DMARC pass rate, policy-applied volume, and the top failing source IPs. Recent rows show source IP, count, disposition, DKIM/SPF alignment, and header-from domain.