Setup checklist#
- ☐ Publish rua=mailto: pointing to a dedicated mailbox or a report processor.
- ☐ Collect reports for at least two weeks before drawing conclusions.
- ☐ Group sources by IP owner and match each to a known vendor.
- ☐ Fix alignment for legitimate sources; treat unknown high-volume sources as spoofing.
- ☐ Track pass rate weekly and tighten policy as it approaches 100%.
Audit checklist#
- ☐ Confirm you are not: reading raw XML by hand and giving up after day two.
- ☐ Confirm you are not: ignoring low-volume unknown sources that turn out to be your own systems.
- ☐ Confirm you are not: expecting RUF reports; most large providers no longer send them.
Ongoing monitoring#
- ☐ Weekly: review provider dashboards (Postmaster Tools, SNDS) and bounce logs
- ☐ Monthly: re-run the setup verification after any vendor or DNS change
- ☐ Quarterly: full audit against this checklist
Frequently asked questions#
How do I read a DMARC report?
Each record lists a source IP, message count, SPF and DKIM results, and alignment. Use an analyzer to aggregate by source; the goal is to name every IP range.
Why do I see mail from IPs I do not recognize?
Common causes are forwarding, a vendor you forgot, an employee's personal tool, or spoofing. Volume and geography usually tell them apart.