Dmarc Overview

Read the Aggregate Reports Explorer

The Aggregate Reports Explorer is where you go from "something failed" to "this IP, from this service, failed this check". Open it from DMARC+ > Aggregate Reports.

Layout

The page has filters at the top, summary cards, charts, and a detail table at the bottom.

Email Overview cards

Card What it counts
All Messages Every message reported in the period
SPF Compliance Messages where SPF passed
DKIM Compliance Messages where DKIM passed
DMARC+ Compliance Messages that passed DMARC (an aligned SPF or DKIM pass)

Note: DMARC compliance is normally equal to or higher than each of SPF and DKIM alone, since one aligned pass is enough. It can be lower than SPF if SPF passes without alignment.

Charts

Chart How to read it
Email Volume Over Time Message counts per day. Spikes can be campaigns or abuse. Gaps can mean reports did not arrive.
Geolocation Where the sending IPs are located
Alignment charts Pie charts of SPF and DKIM alignment. Big "not aligned" slices point at services that sign or send with their own domain.
Report Sources Share of mail by sending service
Compliance (DMARC section) "DMARC authentication status": mail grouped by what the receiver did with it (delivered, quarantined, rejected). This is not an authentication pass rate.
Compliance (DKIM and SPF sections) "DKIM authentication status" and "SPF authentication status": pass and fail counts for each check
Compliance Trend The same status over time, per section. Use the SPF and DKIM trends to confirm a fix worked.

The Aggregate Report table

Each row is one combination of reporter, domain and source IP in the period.

Column Meaning
Reporter The receiver that sent the report
Domain Your domain that the mail claimed to be from
IP Address The sending server's IP
Country Country of that IP
PTR / Server The reverse-DNS name of the IP, which often identifies the service
Volume Message count
Delivery Status What the receiver did with the mail (none, quarantine, reject)
SPF SPF result for this row

The table has more columns than shown here. Open a row to see the full report details, including the DKIM result and selector.

Select a row to open a side pane with the parsed content of the underlying report.

Find the cause of a failure

  1. Filter by domain and set the date range.
  2. Sort or filter the table for failing DMARC.
  3. Note the IP and PTR name. A PTR such as a mail service's hostname usually tells you who it is.
  4. Decide with the table below.
PTR or source Likely explanation Action
Your mail provider Authentication misconfigured Check SPF include and DKIM signing
A marketing, support or billing service Third-party sender not set up See Managing third-party senders
A forwarding service or mailing list Forwarding broke SPF See Troubleshooting
Unknown host, unfamiliar country Possible spoofing Investigate; enforcement will block it

Filters

Domain, group, date range, reporter, country, IP address and DMARC status filters work as on the Dashboard.

Tips

  • Start with the biggest volume of failing mail, not the longest list.
  • Compare a week before and after any change.
  • Use the same date range when comparing domains.
  • Reports are per reporting receiver. Small receivers may report rarely, so a source can seem absent even though it is active.

Limits

  • The Explorer shows what receivers report. It cannot see mail sent to receivers that do not send reports.
  • There is no built-in file export in the Explorer at the time of writing. To share results, use the weekly and PDF reports.