Skip to content

Home Topics Email Authentication DMARC report analysis

Email Authentication · DMARC report analysis

DMARC aggregate reports checklist for 2026

Short answer

A complete DMARC aggregate reports checklist has 5 setup items and 3 things to audit against. Work through setup in order, then schedule a quarterly review.

Setup checklist#

  • ☐ Publish rua=mailto: pointing to a dedicated mailbox or a report processor.
  • ☐ Collect reports for at least two weeks before drawing conclusions.
  • ☐ Group sources by IP owner and match each to a known vendor.
  • ☐ Fix alignment for legitimate sources; treat unknown high-volume sources as spoofing.
  • ☐ Track pass rate weekly and tighten policy as it approaches 100%.

Audit checklist#

  • ☐ Confirm you are not: reading raw XML by hand and giving up after day two.
  • ☐ Confirm you are not: ignoring low-volume unknown sources that turn out to be your own systems.
  • ☐ Confirm you are not: expecting RUF reports; most large providers no longer send them.

Ongoing monitoring#

  • ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
  • ☐ Monthly: re-run the setup verification after any vendor or DNS change
  • ☐ Quarterly: full audit against this checklist

Frequently asked questions#

How do I read a DMARC report?

Each record lists a source IP, message count, SPF and DKIM results, and alignment. Use an analyzer to aggregate by source; the goal is to name every IP range.

Why do I see mail from IPs I do not recognize?

Common causes are forwarding, a vendor you forgot, an employee's personal tool, or spoofing. Volume and geography usually tell them apart.

Analyse your own setup

All analysers
Technical analysis

DMARC record analyser

Grade a DMARC record on enforcement, not just syntax.

Runs in your browser

Keep reading on DMARC report analysis