Ruvalin

Free tool

DMARC report reader

This tool opens the DMARC aggregate reports your mailbox providers send every day, as .xml, .xml.gz or .zip, and summarises them in plain language: how many messages were sent in your name, from which IP addresses, and which of them failed. Everything is parsed in your browser.

Drop your reports here

Several files at once, archives included.

.xml, .xml.gz, .zip

No file is uploaded. Parsing happens entirely in your browser, offline if you like: nothing you drop here reaches our servers or anyone else's.

How to read what you are seeing

An aggregate report contains no message content and no recipient addresses: only counters by source IP. What you are looking for comes down to three questions.

  1. Which IP addresses are sending under my name, and which do I not recognise?
  2. For each recognised source, is alignment achieved through SPF, through DKIM, or through neither?
  3. Is the volume from an unknown source increasing?

A failing source is not necessarily a fraudster

This is the nuance that gives these reports their value, and the one that requires knowing the business. Three causes look very alike on screen.

What you seeWhat it probably is
A known source, failing SPF, passing DKIMAn email provider sending with its own return address. Normal, and harmless while DKIM aligns.
A known source, failing bothA legitimate service that was never configured. This is what to fix before tightening the policy.
An unknown source, low volume, failingOften an automatic forward to a personal address. Not an attack.
An unknown source, rising volume, failingThis is the case that deserves a phone call.

Common questions

CallBook