Dmarc Overview

DMARC+ Dashboard

The Dashboard summarizes mail authentication across your domains for a chosen period. Open it from DMARC+ > Dashboard.

Filters

Filters sit at the top and apply to every widget.

Filter What it does
Domain Limit to one domain
Domain group Limit to a group of domains
Policy Evaluated Filter by the action the receiver took on the message (none, quarantine, reject). This is not the policy you published.
Country Limit to mail from sending IPs in a country
Date range Defaults to the last 15 days
More Filters IP Address; Reporter Domain; DMARC Status (Compliant or Non-Compliant)

Note: the "Reporter Domain" filter matches the base domain of the sending source, not the receiver that sent the report. Treat it as a sender filter.

Tip: the "Policy Evaluated" name is easy to misread. If you published p=quarantine, a message can still show none because the receiver chose not to apply it or pct excluded it.

Widgets

DMARC+ Overview

Counts per protocol (SPF, DKIM, DMARC) in the form "N Valid Record | N Unknown". It counts domains, not messages. Use it to spot domains with missing or unreadable records.

DMARC+ Distribution

Daily bars for total mail, DMARC pass and DMARC fail. A pass means the message passed DMARC through an aligned SPF or DKIM result.

  • Rising fail with flat total: a new source is failing, or spoofing began.
  • Falling total: fewer reports or less mail. Check Troubleshooting.

DKIM Overview

A table of DKIM keys seen in reports: key (selector), fail, pass, total, DKIM domain and From domain. Use it to see which selectors are in use and whether they are your own.

  • A row where the DKIM domain differs from the From domain is a signature that does not align. See What is DKIM?.

Report Sources

Groups mail by the source that sent it. Sources are named where DMARC+ recognizes the sending service, and by base domain otherwise. Use this to find unfamiliar services. See Find shadow senders.

Volume Distribution by Geolocation

A map or list of where sending IPs are located. It shows the location of the servers, not of the recipients.

Tip: use it to spot mail from countries where you have no operations. Do not block a country on this evidence alone, since cloud services send from many regions.

SPF Multi-Domain Overview

A comparison of SPF results across several domains.

Total mail flow over days

A daily line of message counts. Use it to spot spikes, gaps and seasonality.

Domains table

One row per domain with volume, DMARC compliance, SPF pass % and DKIM pass %.

Column How to read it
Volume Messages in the period
DMARC Compliance Share passing DMARC
SPF Pass % Share where SPF passed
DKIM Pass % Share where DKIM passed

Note: SPF pass and DKIM pass are separate from DMARC pass. A message can pass SPF and DKIM yet fail DMARC when the domains do not align.

How the categories are counted

Some charts group mail as Compliant, Non-Compliant, Threat/Unknown and Forwarded. These groups are based on what the receiving server did with the message:

Group Meaning
Compliant Delivered normally (the receiver's action was "none")
Threat/Unknown The receiver quarantined it
Non-Compliant The receiver rejected it
Forwarded The receiver noted a forwarding reason

Important: at p=none, receivers deliver everything, so failing mail is shown as Compliant in these groups. To see true authentication results, use the pass and fail counts and the Aggregate Reports Explorer. See Understand aggregate report data.

Typical review routine

  1. Set the date range to 15 or 30 days.
  2. Look at DMARC+ Distribution for trends.
  3. Open Report Sources and check each new name.
  4. Open the Domains table and sort by lowest DMARC compliance.
  5. For any domain of concern, open the Aggregate Reports Explorer.

Data delay

Data comes from receivers' daily reports. The most recent day is usually incomplete, and some receivers report late.