Dmarc Overview

Understand aggregate report data

This page explains what is inside a DMARC aggregate report and how DMARC+ turns it into the numbers you see.

What a receiver sends

A receiving mail provider sends one XML file per reporting period for each domain that asked for reports. The file is usually compressed (zip or gzip) and arrives by email at your rua address. DMARC+ reads it and stores the results.

Part of the report Contents
Metadata Who reported, the report ID and the time range
Policy published The DMARC policy the receiver saw for your domain
Records One row per group of messages: source IP, count, evaluated result, identifiers and auth results

Fields in a row

Field Meaning
Source IP Server that connected to the receiver
Count Messages in this row
Disposition What the receiver did: none, quarantine or reject
Policy override reason Why the receiver did not apply your policy, for example forwarded or local policy
Header From The visible From domain
Envelope From The domain SPF checked
SPF result Pass or fail for the envelope sender
DKIM result Pass or fail for the signature, with the d= domain and selector
Aligned pass Whether SPF or DKIM passed and aligned with Header From

How results are counted

Measure Definition
DMARC pass An aligned SPF pass or aligned DKIM pass
SPF pass SPF result is pass
DKIM pass The DKIM signature verified
Compliant filter (Dashboard) Both SPF and DKIM passed

Note: "SPF pass" and "DKIM pass" describe the check on its own. DMARC pass also requires alignment. This is why a domain can show 100% SPF pass and still fail DMARC.

Note: the Dashboard "Compliant" filter is stricter than DMARC itself, because it requires both SPF and DKIM. A message that passes DMARC on DKIM alone is not "Compliant" under that filter.

Disposition-based groups

The Compliant, Non-Compliant, Threat/Unknown and Forwarded groups used in some charts and in the weekly report come from the receiver's disposition, not from authentication results. See Dashboard.

You published Failing mail is likely shown as
p=none Compliant (delivered normally)
p=quarantine Threat/Unknown
p=reject Non-Compliant

So after you move to enforcement, the Non-Compliant count rises because receivers are now acting on failures. That is the expected outcome.

Timing and completeness

  • Reports cover a fixed window (often a day) and arrive after it closes.
  • Receivers differ in which reports they send and how often.
  • Very low volume domains may get no report on quiet days.
  • Reports reflect the messages the receiver processed, not a complete log of everything you sent.

Sending sources

DMARC+ groups source IPs into named sources:

  • IPs that fall inside your published SPF record are grouped as SPF-identified sources.
  • Other IPs are matched against a directory of known sending services.
  • Anything unmatched is shown by the base domain of its reverse-DNS name.

Note: a group based on your SPF record depends on your current record. An IP you removed from SPF recently can move from "SPF identified" to another group.

Privacy

Aggregate reports contain IP addresses and counts, not message content. Forensic reports may include subjects and addresses. See Forensic reports.