mailtanimailtani
Free Tool

Free DMARC Analyzer

Paste your DMARC aggregate report XML and instantly parse it into a readable summary. See which sources are passing and failing authentication at a glance.

Paste your DMARC aggregate report XML

How to Use This Tool

Step 01

Get your DMARC report

DMARC aggregate reports arrive by email as attached XML files (often gzip-compressed). Open the XML file in a text editor and copy the full contents.

Step 02

Paste and parse

Paste the raw XML into the analyzer. The tool parses it instantly in your browser and presents the results in a readable table.

Step 03

Act on the findings

Add missing legitimate senders to your SPF record, configure DKIM for sources that are failing, and advance your DMARC policy as your pass rate improves.

What DMARC Aggregate Reports Contain and Why They Matter

DMARC aggregate reports (rua reports) are the email authentication equivalent of server access logs. Sent daily by participating inbox providers — including Google, Microsoft, Yahoo, and many others — they document every IP address that sent email claiming your domain over the reporting period, along with the SPF and DKIM results for each sending source. This data is the ground truth about your domain's authentication posture: it shows you what is actually happening in the wild, not what you think is happening based on your configuration.

Each report arrives as an XML file attached to an email sent to the address in your DMARC record's rua= tag. The XML is compact and machine-readable but difficult to interpret by eye. A typical report from a major inbox provider might cover thousands of messages across dozens of sending IPs, with SPF and DKIM results for each. Without a parser, extracting actionable intelligence from this XML requires manual effort that most teams simply do not do — meaning they publish a DMARC record but never look at the data it generates.

The consequence of not reading DMARC reports is that authentication failures go unnoticed. A third-party CRM that sends from your domain without DKIM alignment, an old sending IP range that still appears in your email stream despite being decommissioned, a new ESP whose SPF include was missed — all of these appear in DMARC reports. Ignored, they accumulate as unexplained DMARC failures that limit how aggressively you can enforce policy and signal to inbox providers that your authentication is incomplete.

How to Read the Parsed Results

A DMARC aggregate report, once parsed, contains a small number of critical data points. The reporting organisation (who sent you the report), the date range covered, the policy that was applied (none, quarantine, or reject), and the actual SPF and DKIM disposition for each source IP and their message count.

The most important field is whether DMARC passed or failed for each source. A source is passing DMARC if at least one of SPF or DKIM is aligned — meaning the domain in the relevant authentication check matches the organisational domain in the From header. A source is failing DMARC if both SPF and DKIM fail the alignment check. Failing sources are the ones you need to investigate.

For each failing source, the questions to ask are: do I recognise this IP as a legitimate sender for my domain? If yes, why is authentication failing — is SPF configured correctly for this sender, and is DKIM signing enabled? If no, is this spoofing (someone using my domain without authorisation)? The distinction determines the remediation: add missing authentication for legitimate senders, or advance DMARC policy toward reject to block spoofing attempts.

Moving from Monitoring to Enforcement Using Report Data

The canonical DMARC deployment path is three stages: none (monitor), quarantine (soft enforce), reject (full enforce). Most teams get stuck at none because they never engage with the report data needed to move forward with confidence. The analyzer closes this gap by making the report data immediately actionable.

The target before advancing from none to quarantine is a DMARC pass rate above 95 percent for your legitimate sending volume. This means that of all the messages sent from your domain that appear in DMARC reports, at least 95 percent have SPF or DKIM aligned. The remaining failures should be investigated: some will be legitimate senders you can fix, others will be spoofing that will be blocked once you enforce policy.

The pct= tag in your DMARC record lets you enforce policy on a percentage of failing messages. Starting at pct=10 with p=quarantine, then increasing to pct=50, then pct=100, then changing to p=reject with pct=100 is a staged approach that limits blast radius if you missed a legitimate sender. At each stage, read the DMARC reports to confirm the change has not caused unexpected failures in legitimate mail before advancing.

Practical Report Management: Volumes, Providers, and Automation

At higher sending volumes, the volume of DMARC aggregate reports becomes substantial. A single campaign sent to 100,000 addresses may generate reports from 20–30 different inbox providers covering thousands of message records. Managing this manually through a single email inbox becomes impractical quickly.

Dedicated DMARC reporting services — including both commercial platforms and open-source tools — accept your rua= reports, parse them continuously, and present the data through dashboards with trend analysis, anomaly detection, and sender alignment tracking. For domains with significant sending volume, this level of tooling is warranted. For smaller senders, the manual approach of parsing individual reports when they arrive is entirely workable, particularly when the analyzer makes the parsing instant.

The ruf= tag for forensic (failure) reports is worth understanding but should not be relied upon as a primary diagnostic tool. Many major inbox providers no longer send ruf reports due to privacy concerns — they would expose recipient email addresses and message content. Aggregate rua reports are the primary and most widely supported reporting mechanism.

Key Features

Browser-Side XML Parsing

Parses the DMARC XML entirely in your browser — nothing is sent to any server.

Source IP Table

Lists every sending source IP with message count, SPF result, DKIM result, and DMARC disposition.

Pass/Fail Summary

Shows total message count and the percentage of messages that passed DMARC, giving you an instant health score.

Policy Applied Display

Shows which DMARC policy (none, quarantine, reject) was in effect during the reporting period.

Reporter Identity

Identifies which inbox provider sent the report so you know whose data you are looking at.

Date Range Display

Shows the exact time window covered by the report to help you correlate results with known sends.

Frequently Asked Questions

Make DMARC Work for You

mailtani walks you through SPF, DKIM, and DMARC setup and monitors your authentication status automatically — all included at one price.

  • DMARC setup walkthrough included
  • Aggregate report monitoring
  • Inbox warmup & rotation
  • One-time price

14-day free trial · €89 lifetime access after