DMARC Report Analyzer — Read Your Report in Plain English

Mailbox providers email you DMARC aggregate reports as dense XML — machine-shaped, not human-shaped. Paste one below (or upload the .xml, .xml.gz or .zip exactly as it arrived) and get the same plain-English translation our monitoring produces: who sent as your domain, how much passed, and what to fix first.

No signup. Your report is analyzed in memory and never stored — nothing is written to disk, a database, or logs.

How to read a DMARC report

Every aggregate report answers three questions, and this analyzer pulls them out for you:

  • Who sent as your domain? Each row is a source IP with a message count — your real mail servers, your newsletter tool, and anyone else using your name.
  • Did it authenticate? A message passes DMARC when SPF or DKIM passes and aligns with your From domain. The pass rate here is volume-weighted, the same way we score it in weekly monitoring.
  • What happens to failures? Your published policy (p=none, quarantine or reject) decides whether failing mail is delivered anyway, sent to spam, or blocked.

For a full walkthrough of the raw XML fields, read our guide: How to read DMARC reports (without losing your mind).

Get weekly DMARC monitoring →

What a DMARC aggregate report is

Once you publish a rua= address, mailbox providers email you a daily aggregate report — an XML file summarising every message that claimed to be from your domain. It is machine-shaped on purpose, which is why it is hard to read by hand. Paste one here (or upload the .xml, .xml.gz or .zip exactly as it arrived) and this tool translates it into plain English.

It works as a free DMARC report analyser: the DMARC analyser reads the raw report and turns every row into one readable line, so you do not need a separate DMARC XML analyzer or a spreadsheet to make sense of it.

What is inside the XML

Each report has three parts:

  • Report metadata — who sent the report (Google, Yahoo, Microsoft, and so on) and the date range it covers.
  • Published policy — the DMARC record you had live at the time: your p= policy and your alignment settings.
  • Records — the heart of it. One row per sending source, each with the source IP, a count of messages, the disposition (what the receiver did — none, quarantine or reject), and the SPF and DKIM results.

Reading the rows

Two things decide each row: did SPF or DKIM pass, and did the passing domain align with your From address. A message can pass SPF for a different domain and still fail DMARC — that gap is alignment, and it is the most common reason “everything looks fine” but DMARC still fails. Group the rows by source: your own mail servers and authorised tools should pass and align; anything else is either a sender you forgot to authenticate or someone spoofing you.

What to fix first

Start with legitimate sources that are failing — a newsletter tool without a DKIM key, a subdomain nobody set up. Fix those, watch a few more reports, and once only real spoofers are left failing you can safely move your policy to p=reject. There is a worked example in how to read DMARC reports.

Common questions

What is an aggregate (rua) report?

A daily XML summary from each mailbox provider of all mail claiming to be from your domain. It contains no message content.

SPF passed but DMARC failed — why?

Alignment. SPF passed for a different domain than the one your reader sees. DKIM or SPF must align with your From domain for DMARC to pass.

My report shows failures — am I being spoofed?

Maybe, or a legitimate sender is unauthenticated. Identify the source IP and the sending service before deciding.

Is this a DMARC report analyser?

Yes. It is a free DMARC report analyser (or DMARC analyser): paste or upload the raw DMARC XML and this DMARC XML analyzer explains every row in plain English, with no signup.

A one-off check is a snapshot — DMARC needs watching

PlainDMARC monitors your domains continuously and sends a weekly plain-English verdict per domain — what passed, what failed, and what to fix.

14-day free trial · One DNS record · Free plan available — no card