Docs

DMARC Analyzer

Monitor domains and review DMARC aggregate reports.

toolboxdmarcreportsdomains

DMARC Analyzer

The DMARC Analyzer is available when the Workspace has the dmarc_reports feature and your role can read it. It helps review DMARC aggregate reports for monitored domains.

  • Create one monitor per domain. Domains are normalized, and monitors can be active or paused.
  • Monitors that already have imported reports cannot be deleted; pause them when ingestion should stop.
  • Attach an active IMAP mailbox to a monitor when you also have Workspace settings management access. The picker includes Gmail, standard IMAP, and native iCloud mailboxes. When a directly connected mailbox has no individual account scope, Einblick labels it as Workspace-wide before selection. Active monitors use the chosen mailbox to ingest matching DMARC report attachments automatically.
  • Upload aggregate report files manually as XML, ZIP, GZIP, or .xml.gz. Raw uploads are capped at 25 MB.
  • ZIP uploads can contain up to 25 XML reports. Each XML report is capped at 5 MB after decompression, and one import can contain up to 5,000 aggregate rows.
  • Raw uploaded files are stored in the system DMARC Reports folder in Files.
  • Duplicate aggregate reports are detected by fingerprint and marked as duplicate instead of being imported again.
  • The dashboard shows total volume, DMARC pass rate, policy-applied volume, and the top failing source IPs. Recent rows show source IP, count, disposition, DKIM/SPF alignment, and header-from domain.