DMARC reports

Every day, each provider that receives mail in your name sends you a report saying exactly who sent as you and what passed. Nobody reads them, because they arrive as compressed XML.

What is in them

For each machine that sent mail claiming to be your domain: its IP address, how many messages, and whether SPF and DKIM lined up. That is the answer to two questions you cannot otherwise answer — is somebody forging my domain? and which of my own tools is failing?

The second one is the common case. A newsletter service, a CRM, your accountant's system: all of them send as you, and any of them can be missing from your SPF record without anybody noticing until invoices start landing in spam.

You do not have to set anything up

When you add a domain, the DMARC record we give you asks for the reports to go to two places: your own address, and ours. We also publish, in our own zone, the record that authorises that — yourdomain._report._dmarc.oltrano.com.

That authorisation record is the step everyone misses. RFC 7489 says that if you want reports for yourdomain.com delivered to an address at a different domain, that other domain has to publish a record agreeing to it. Without it the big providers simply do not send the report — no error, no bounce, no explanation. You wait two weeks and conclude it does not work.

What you see

Open DMARC in the sidebar. At the top: how many messages were seen, how many passed, and what your policy currently tells receivers to do. Then a line in plain words — that is the part that matters:

Reading one by hand

Got a report sitting in your inbox already? Drop the .xml, .gz or .zip attachment onto the DMARC screen. We read it and keep the figures, same as the ones that arrive on their own.

Why DKIM matters more than the internet says

DMARC passes when either SPF or DKIM lines up, not both. SPF breaks the moment anyone forwards your message, because the forwarding server is not on your list. DKIM survives, because the signature travels with the message. So a domain relying on SPF alone fails every time a customer forwards an invoice internally — which is exactly what customers do with invoices.

Questions people actually ask

Do I have to pay for a DMARC service?

Not for this. Reading aggregate reports is the part people buy a separate product for, and it is included here.

Why have I not received any reports?

Give it two or three days — they come once a day per provider, and only when someone actually sent mail as you. If a week passes with real traffic, the authorisation record is the usual culprit, and we publish that one ourselves.

Someone is sending as my domain. What do I do?

If DMARC is at p=none, receivers are told to do nothing. Move to quarantine once your own senders all pass, then to reject. That is what makes forgery actually stop.

Next

← All guides