What GDPR and ePrivacy requires#
GDPR requires a lawful basis (usually consent) for marketing email and documented consent records.
What DMARC aggregate reports are#
DMARC aggregate (RUA) reports are daily XML files sent by mailbox providers listing, per sending IP, how many messages claimed your domain and whether they passed SPF, DKIM, and alignment. Forensic (RUF) reports contain samples of individual failures.
Why it matters#
Reports are the only way to see who is sending as your domain, including vendors you forgot and attackers you never knew about. Moving to p=reject safely depends on reading them.
How DMARC aggregate reports supports GDPR and ePrivacy compliance#
Regulators and recipients need to identify who sent a message and trust that opt-out mechanisms work. DMARC aggregate reports contributes by reports are the only way to see who is sending as your domain, including vendors you forgot and attackers you never knew about. Moving to p=reject safely depends on reading them.
Implementation steps#
- Publish rua=mailto: pointing to a dedicated mailbox or a report processor.
- Collect reports for at least two weeks before drawing conclusions.
- Group sources by IP owner and match each to a known vendor.
- Fix alignment for legitimate sources; treat unknown high-volume sources as spoofing.
- Track pass rate weekly and tighten policy as it approaches 100%.
<record>
<row><source_ip>203.0.113.10</source_ip><count>412</count>
<policy_evaluated><disposition>none</disposition><dkim>pass</dkim><spf>fail</spf></policy_evaluated></row>
<identifiers><header_from>example.com</header_from></identifiers>
</record>Frequently asked questions#
How do I read a DMARC report?
Each record lists a source IP, message count, SPF and DKIM results, and alignment. Use an analyzer to aggregate by source; the goal is to name every IP range.
Why do I see mail from IPs I do not recognize?
Common causes are forwarding, a vendor you forgot, an employee's personal tool, or spoofing. Volume and geography usually tell them apart.