DMARC Report Analyser

DMARC Report Analyser

DMARC aggregate reports arrive as compressed XML that nobody can read. Drop one here and it becomes a plain summary of who sent mail as your domain and whether it passed.

The file is parsed in your browser. Nothing is uploaded and nothing is stored.

How to use

  1. Save the report attachment from the DMARC mailbox you set as your rua address.
  2. Drop the file in above. Gzip and zip archives are unpacked for you.
  3. Read the source list. Any high-volume sender failing both SPF and DKIM is either a service you forgot to authenticate, or someone spoofing you.

Frequently asked questions

Which formats are supported?
Raw XML, gzipped XML and single-file zip archives, which covers what Google, Microsoft, Yahoo and the other big reporters send.
Why does a legitimate service show as failing?
Usually alignment. The service may pass SPF for its own domain while the visible From domain is yours, which DMARC does not accept. Add a DKIM key signing with your domain.
How often should I read these?
Weekly while you are rolling out DMARC, then monthly once the policy is at reject and the sources look stable.