Understand aggregate report data
This page explains what is inside a DMARC aggregate report and how DMARC+ turns it into the numbers you see.
What a receiver sends
A receiving mail provider sends one XML file per reporting period for each domain that asked for reports. The file is usually compressed (zip or gzip) and arrives by email at your rua address. DMARC+ reads it and stores the results.
| Part of the report | Contents |
|---|---|
| Metadata | Who reported, the report ID and the time range |
| Policy published | The DMARC policy the receiver saw for your domain |
| Records | One row per group of messages: source IP, count, evaluated result, identifiers and auth results |
Fields in a row
| Field | Meaning |
|---|---|
| Source IP | Server that connected to the receiver |
| Count | Messages in this row |
| Disposition | What the receiver did: none, quarantine or reject |
| Policy override reason | Why the receiver did not apply your policy, for example forwarded or local policy |
| Header From | The visible From domain |
| Envelope From | The domain SPF checked |
| SPF result | Pass or fail for the envelope sender |
| DKIM result | Pass or fail for the signature, with the d= domain and selector |
| Aligned pass | Whether SPF or DKIM passed and aligned with Header From |
How results are counted
| Measure | Definition |
|---|---|
| DMARC pass | An aligned SPF pass or aligned DKIM pass |
| SPF pass | SPF result is pass |
| DKIM pass | The DKIM signature verified |
| Compliant filter (Dashboard) | Both SPF and DKIM passed |
Note: "SPF pass" and "DKIM pass" describe the check on its own. DMARC pass also requires alignment. This is why a domain can show 100% SPF pass and still fail DMARC.
Note: the Dashboard "Compliant" filter is stricter than DMARC itself, because it requires both SPF and DKIM. A message that passes DMARC on DKIM alone is not "Compliant" under that filter.
Disposition-based groups
The Compliant, Non-Compliant, Threat/Unknown and Forwarded groups used in some charts and in the weekly report come from the receiver's disposition, not from authentication results. See Dashboard.
| You published | Failing mail is likely shown as |
|---|---|
p=none |
Compliant (delivered normally) |
p=quarantine |
Threat/Unknown |
p=reject |
Non-Compliant |
So after you move to enforcement, the Non-Compliant count rises because receivers are now acting on failures. That is the expected outcome.
Timing and completeness
- Reports cover a fixed window (often a day) and arrive after it closes.
- Receivers differ in which reports they send and how often.
- Very low volume domains may get no report on quiet days.
- Reports reflect the messages the receiver processed, not a complete log of everything you sent.
Sending sources
DMARC+ groups source IPs into named sources:
- IPs that fall inside your published SPF record are grouped as SPF-identified sources.
- Other IPs are matched against a directory of known sending services.
- Anything unmatched is shown by the base domain of its reverse-DNS name.
Note: a group based on your SPF record depends on your current record. An IP you removed from SPF recently can move from "SPF identified" to another group.
Privacy
Aggregate reports contain IP addresses and counts, not message content. Forensic reports may include subjects and addresses. See Forensic reports.