Free tool
DMARC report reader
This tool opens the DMARC aggregate reports your mailbox providers send every day, as .xml, .xml.gz or .zip, and summarises them in plain language: how many messages were sent in your name, from which IP addresses, and which of them failed. Everything is parsed in your browser.
Drop your reports here
Several files at once, archives included.
.xml, .xml.gz, .zip
No file is uploaded. Parsing happens entirely in your browser, offline if you like: nothing you drop here reaches our servers or anyone else's.
How to read what you are seeing
An aggregate report contains no message content and no recipient addresses: only counters by source IP. What you are looking for comes down to three questions.
- Which IP addresses are sending under my name, and which do I not recognise?
- For each recognised source, is alignment achieved through SPF, through DKIM, or through neither?
- Is the volume from an unknown source increasing?
A failing source is not necessarily a fraudster
This is the nuance that gives these reports their value, and the one that requires knowing the business. Three causes look very alike on screen.
| What you see | What it probably is |
|---|---|
| A known source, failing SPF, passing DKIM | An email provider sending with its own return address. Normal, and harmless while DKIM aligns. |
| A known source, failing both | A legitimate service that was never configured. This is what to fix before tightening the policy. |
| An unknown source, low volume, failing | Often an automatic forward to a personal address. Not an attack. |
| An unknown source, rising volume, failing | This is the case that deserves a phone call. |