technical · sourced answer

How to Read DMARC Aggregate Reports

To read DMARC aggregate reports, you must unzip the XML file sent by receiving mail servers and parse the record tags to identify which IP addresses are sending mail on your behalf and whether they pass SPF and DKIM alignment. Because these reports are in raw XML format, most developers use a parser or a tool like SendHQ free tools (https://sendhq.cc/tools) to visualize the data.

Understanding the XML Structure

DMARC aggregate reports use an XML schema. The report contains a record section for each source IP address. Within each record, you will find the source IP, the count of messages sent from that IP, and a set of policy evaluations. The policy evaluation section details whether the message passed or failed SPF and DKIM checks and whether those results aligned with the header from domain.

Analyzing SPF and DKIM Alignment

A pass result in the report means the authentication check succeeded, but alignment is what matters for DMARC. SPF alignment occurs when the domain in the Return-Path matches the domain in the From header. DKIM alignment occurs when the d= tag in the DKIM signature matches the From header domain. If both fail, the message fails DMARC regardless of the individual check results.

Identifying Unauthorized Senders

Scan the report for IP addresses that you do not recognize. If an IP shows a high volume of mail with SPF and DKIM failures, it is likely an unauthorized sender or a misconfigured third party service. Compare these IPs against your known infrastructure and vendor lists to determine if you need to update your SPF record or provide a DKIM key to a legitimate partner.

Interpreting the Disposition

The disposition tag tells you what the receiving server did with the email based on your current DMARC policy. If your policy is p=none, the disposition is usually none, meaning the mail was delivered despite failures. If p=quarantine, the mail may have been sent to spam. If p=reject, the mail was blocked entirely. Use these metrics to safely move from none to reject.

Questions teams ask

Why are DMARC reports sent as zipped XML files?

XML allows for structured data that can be processed by machines, and compression reduces the bandwidth required to send large volumes of aggregate data daily.

How often are these reports generated?

Most receiving mail servers send aggregate reports once every 24 hours, though the timing varies by provider.

What is the difference between aggregate and forensic reports?

Aggregate reports provide high level statistics on mail streams, while forensic reports provide detailed examples of specific failed messages.

Primary sources