DMARC reports
Every day, each provider that receives mail in your name sends you a report saying exactly who sent as you and what passed. Nobody reads them, because they arrive as compressed XML.
What is in them
For each machine that sent mail claiming to be your domain: its IP address, how many messages, and whether SPF and DKIM lined up. That is the answer to two questions you cannot otherwise answer — is somebody forging my domain? and which of my own tools is failing?
The second one is the common case. A newsletter service, a CRM, your accountant's system: all of them send as you, and any of them can be missing from your SPF record without anybody noticing until invoices start landing in spam.
You do not have to set anything up
When you add a domain, the DMARC record we give you asks for the reports to go to two places:
your own address, and ours. We also publish, in our own zone, the record that authorises that —
yourdomain._report._dmarc.oltrano.com.
That authorisation record is the step everyone misses. RFC 7489 says that if
you want reports for yourdomain.com delivered to an address at a different domain,
that other domain has to publish a record agreeing to it. Without it the big providers simply do
not send the report — no error, no bounce, no explanation. You wait two weeks and conclude it
does not work.
What you see
Open DMARC in the sidebar. At the top: how many messages were seen, how many passed, and what your policy currently tells receivers to do. Then a line in plain words — that is the part that matters:
- "203.0.113.10 sent 9 messages as you that did not pass." If you recognise the sender, add it to your SPF record or have it sign with DKIM. If you do not, somebody is sending as your domain.
- "4 senders pass DKIM but fail SPF." That is forwarding, and it is normal. The forwarding server is not in your SPF record, but your DKIM signature survives the trip. Nothing to fix.
- "Almost everything passes, you are still on p=none." Time to move to
p=quarantine, watch for a fortnight, then considerp=reject.
Reading one by hand
Got a report sitting in your inbox already? Drop the .xml, .gz or
.zip attachment onto the DMARC screen. We read it and keep the figures, same as the
ones that arrive on their own.
Why DKIM matters more than the internet says
DMARC passes when either SPF or DKIM lines up, not both. SPF breaks the moment anyone forwards your message, because the forwarding server is not on your list. DKIM survives, because the signature travels with the message. So a domain relying on SPF alone fails every time a customer forwards an invoice internally — which is exactly what customers do with invoices.
Questions people actually ask
Do I have to pay for a DMARC service?
Not for this. Reading aggregate reports is the part people buy a separate product for, and it is included here.
Why have I not received any reports?
Give it two or three days — they come once a day per provider, and only when someone actually sent mail as you. If a week passes with real traffic, the authorisation record is the usual culprit, and we publish that one ourselves.
Someone is sending as my domain. What do I do?
If DMARC is at p=none, receivers are told to do nothing. Move to quarantine once your own senders all pass, then to reject. That is what makes forgery actually stop.
Next
- SPF, DKIM and DMARC without the folkloreWhat each one does, what breaks them, and what to actually set.
- Set up email on your own domainThe DNS records, what each one does, and the one-click path.