Free DMARC Analyzer
Paste your DMARC aggregate report XML and instantly parse it into a readable summary. See which sources are passing and failing authentication at a glance.
How to Use This Tool
Get your DMARC report
DMARC aggregate reports arrive by email as attached XML files (often gzip-compressed). Open the XML file in a text editor and copy the full contents.
Paste and parse
Paste the raw XML into the analyzer. The tool parses it instantly in your browser and presents the results in a readable table.
Act on the findings
Add missing legitimate senders to your SPF record, configure DKIM for sources that are failing, and advance your DMARC policy as your pass rate improves.
What DMARC Aggregate Reports Contain and Why They Matter
DMARC aggregate reports (rua reports) are the email authentication equivalent of server access logs. Sent daily by participating inbox providers — including Google, Microsoft, Yahoo, and many others — they document every IP address that sent email claiming your domain over the reporting period, along with the SPF and DKIM results for each sending source. This data is the ground truth about your domain's authentication posture: it shows you what is actually happening in the wild, not what you think is happening based on your configuration.
Each report arrives as an XML file attached to an email sent to the address in your DMARC record's rua= tag. The XML is compact and machine-readable but difficult to interpret by eye. A typical report from a major inbox provider might cover thousands of messages across dozens of sending IPs, with SPF and DKIM results for each. Without a parser, extracting actionable intelligence from this XML requires manual effort that most teams simply do not do — meaning they publish a DMARC record but never look at the data it generates.
The consequence of not reading DMARC reports is that authentication failures go unnoticed. A third-party CRM that sends from your domain without DKIM alignment, an old sending IP range that still appears in your email stream despite being decommissioned, a new ESP whose SPF include was missed — all of these appear in DMARC reports. Ignored, they accumulate as unexplained DMARC failures that limit how aggressively you can enforce policy and signal to inbox providers that your authentication is incomplete.
How to Read the Parsed Results
A DMARC aggregate report, once parsed, contains a small number of critical data points. The reporting organisation (who sent you the report), the date range covered, the policy that was applied (none, quarantine, or reject), and the actual SPF and DKIM disposition for each source IP and their message count.
The most important field is whether DMARC passed or failed for each source. A source is passing DMARC if at least one of SPF or DKIM is aligned — meaning the domain in the relevant authentication check matches the organisational domain in the From header. A source is failing DMARC if both SPF and DKIM fail the alignment check. Failing sources are the ones you need to investigate.
For each failing source, the questions to ask are: do I recognise this IP as a legitimate sender for my domain? If yes, why is authentication failing — is SPF configured correctly for this sender, and is DKIM signing enabled? If no, is this spoofing (someone using my domain without authorisation)? The distinction determines the remediation: add missing authentication for legitimate senders, or advance DMARC policy toward reject to block spoofing attempts.
Moving from Monitoring to Enforcement Using Report Data
The canonical DMARC deployment path is three stages: none (monitor), quarantine (soft enforce), reject (full enforce). Most teams get stuck at none because they never engage with the report data needed to move forward with confidence. The analyzer closes this gap by making the report data immediately actionable.
The target before advancing from none to quarantine is a DMARC pass rate above 95 percent for your legitimate sending volume. This means that of all the messages sent from your domain that appear in DMARC reports, at least 95 percent have SPF or DKIM aligned. The remaining failures should be investigated: some will be legitimate senders you can fix, others will be spoofing that will be blocked once you enforce policy.
The pct= tag in your DMARC record lets you enforce policy on a percentage of failing messages. Starting at pct=10 with p=quarantine, then increasing to pct=50, then pct=100, then changing to p=reject with pct=100 is a staged approach that limits blast radius if you missed a legitimate sender. At each stage, read the DMARC reports to confirm the change has not caused unexpected failures in legitimate mail before advancing.
Practical Report Management: Volumes, Providers, and Automation
At higher sending volumes, the volume of DMARC aggregate reports becomes substantial. A single campaign sent to 100,000 addresses may generate reports from 20–30 different inbox providers covering thousands of message records. Managing this manually through a single email inbox becomes impractical quickly.
Dedicated DMARC reporting services — including both commercial platforms and open-source tools — accept your rua= reports, parse them continuously, and present the data through dashboards with trend analysis, anomaly detection, and sender alignment tracking. For domains with significant sending volume, this level of tooling is warranted. For smaller senders, the manual approach of parsing individual reports when they arrive is entirely workable, particularly when the analyzer makes the parsing instant.
The ruf= tag for forensic (failure) reports is worth understanding but should not be relied upon as a primary diagnostic tool. Many major inbox providers no longer send ruf reports due to privacy concerns — they would expose recipient email addresses and message content. Aggregate rua reports are the primary and most widely supported reporting mechanism.
Key Features
Browser-Side XML Parsing
Parses the DMARC XML entirely in your browser — nothing is sent to any server.
Source IP Table
Lists every sending source IP with message count, SPF result, DKIM result, and DMARC disposition.
Pass/Fail Summary
Shows total message count and the percentage of messages that passed DMARC, giving you an instant health score.
Policy Applied Display
Shows which DMARC policy (none, quarantine, reject) was in effect during the reporting period.
Reporter Identity
Identifies which inbox provider sent the report so you know whose data you are looking at.
Date Range Display
Shows the exact time window covered by the report to help you correlate results with known sends.
Frequently Asked Questions
Related Tools
Continue your email deliverability setup with these free tools.
Tools Are Just the Start
Once your domain is set up, mailtani handles sending, warmup, sequences, and rotation.
See How mailtani Compares
From the Blog
Make DMARC Work for You
mailtani walks you through SPF, DKIM, and DMARC setup and monitors your authentication status automatically — all included at one price.
- DMARC setup walkthrough included
- Aggregate report monitoring
- Inbox warmup & rotation
- One-time price
14-day free trial · €89 lifetime access after
