DMARC Analyzer
Collect DMARC aggregate reports from a mailbox and see who sends as your domains.
toolboxdmarcreportsdomains
DMARC Analyzer
The DMARC Analyzer is available when the Workspace has the dmarc_reports feature and your role can read it. Mail providers such as Google, Microsoft and Yahoo send a daily aggregate report to the address in a domain's DMARC record (rua=). The analyzer collects these reports from a mailbox in the background and shows who sends email as your domains and whether it authenticates.
Collecting reports
- Open Report mailboxes and switch on the mailbox your DMARC record sends reports to. Gmail, standard IMAP and iCloud mailboxes connected in System Settings -> Email are listed. Choosing mailboxes requires Workspace settings management access.
- While mail is synced, report attachments from the chosen mailboxes are imported automatically. As long as no mailbox is chosen, every connected mailbox is checked once at least one domain is monitored.
- Choosing a mailbox also scans its recent history (90 days by default) so reports you already received are imported. Scan history repeats the scan for 30 to 365 days. A scan is read-only, skips attachments that were already imported, and stops early for very large mailboxes; run it again to continue.
- Report files can also be uploaded manually as XML, ZIP, GZIP or
.xml.gz(up to 25 MB). ZIP files may contain up to 25 XML reports, each up to 5 MB unpacked, and one import may contain up to 5,000 rows. Raw files are stored in the systemDMARC Reportsfolder in Files.
Domains
- A domain appears automatically when its first report arrives. You can also add one manually.
- Pausing a domain skips its future reports. Domains that already have reports cannot be removed; pause them instead.
What the analyzer shows
- Overview: message volume, DMARC pass rate, DKIM and SPF alignment, quarantined or rejected mail, a daily trend, the reporting providers, and the sending sources that need attention. Choose a domain and a period (7 to 365 days); report dates are counted by the reporter's period in UTC.
- Sending sources: every server that sent mail as your domain, with its reverse DNS name, the DKIM signer, and a plain-language diagnosis of why it fails. A legitimate service that fails usually needs SPF or DKIM set up for your domain; an unknown server that fails may be spoofing it.
- Reports: every received report. Open one to see its rows and the raw DKIM and SPF results.
- Domains: the published policy (
p=,pct=), volume, pass rate and last report per domain.p=noneonly observes; failing mail is still delivered until the domain enforcesquarantineorreject. - Imports: every received file and what became of it. Failed imports show the error and can be retried; a retry discards whatever the failed attempt stored. Reports that were already imported are marked as duplicates.