taktekbot

Free tool

Read your DMARC reports: a free reader that opens the .zip and .gz files

Every server sending email as your domain, in one list. The files never leave this page.

Drop in a DMARC report as it arrived (.zip, .gz or .xml) to see which servers fail DMARC and what to fix.

Step 1: add your reports

Drop files here, or .

Or paste the XML

What this reads, and where the reports come from

To read a DMARC report, drop the attachment here: the .zip, .gz or .xml file, as it arrived. If you saved the whole email instead (an .eml file), drop that: the page finds the report attached inside. This page opens it in your browser and lists every server that sent email using your domain, how many messages each sent, whether they passed DMARC, and what to fix for the ones that failed. Nothing is uploaded.

The reports come from the rua= address in your DMARC record. Each receiver that got mail "from" your domain (Gmail, Outlook.com, Yahoo and others) usually sends one a day. If you don't get any yet, set up the record first: why business emails go to spam, and how to fix SPF, DKIM and DMARC walks through it.

Reading the result

Each line is one server (an IP address) that sent mail with your domain in the From: line, added up across all the reports you dropped in. Failing servers come first, biggest first.

  • PASS means the receiver saw SPF or DKIM pass for your own domain. That message is safe when you tighten your policy.
  • FAIL means neither did. With p=quarantine these messages go to spam; with p=reject they bounce.

The domains on each line are your best clue to who the sender is. An SPF result "for bounces.something.com" or a DKIM signature "for something.com" names the service that sent it: your newsletter tool, your shop, your booking system. The IP link looks up who owns the address on a third-party site (it sends that IP there, nothing else).

What to do about each failure

  1. DKIM passes, but for another domain. A service is signing your mail with its own domain. In that service's settings, look for "custom domain", "domain authentication" or "DKIM", add the records it gives you, and turn signing on. Once it signs as your domain, the line turns to PASS.
  2. SPF passes, but for another domain. The service uses its own bounce address. That's normal, and it doesn't count for DMARC. Fix DKIM as above; some services also let you set a custom return-path on your domain.
  3. Nothing passes, and you recognise the sender. A forgotten system: an old website, an accounting app sending invoices, a scanner that emails. Add it to your SPF record or turn on DKIM in it. If you can't, send its mail from a different address or a subdomain.
  4. Nothing passes, and the IP belongs to nobody you use. Someone else is sending as your domain, or it's spam with a forged From:. That's the mail p=reject is for. You don't need to do anything for that source.
  5. DKIM or SPF passes for a subdomain of yours, and your record has adkim=s or aspf=s. Strict alignment needs the exact domain in the From: line, so a signature for mail.example.com doesn't count for mail from example.com. Set the service to use the exact domain, or remove the s tag: the default, relaxed, accepts subdomains.
  6. SPF fails but DKIM passes for your domain. Usually forwarding: someone's mailbox forwards your email on, so the IP changes but the signature survives. The line already shows PASS. Nothing to fix.

When to move past p=none

Collect two to four weeks of reports. When every sender you recognise shows PASS and what's left failing is either forwarding or senders you don't know, change your DMARC record from p=none to p=quarantine. Keep reading the reports for another few weeks, then move to p=reject. If a real sender shows up failing after the change, fix it, or step back to p=none while you do.

The "disposition" on a line tells you what the receiver did: none delivered it, quarantine sent it to spam, reject refused it. Under p=none everything says none, so failures cost you nothing yet. That's why you read reports before you tighten.

Reading one record by hand

If you'd rather read the XML yourself, open the file in a text editor (unzip it first). Each sender is one <record>. This is the part that matters, trimmed:

<row>
  <source_ip>198.51.100.25</source_ip>   the server that sent it
  <count>86</count>                     how many messages
  <policy_evaluated>
    <disposition>none</disposition>     what the receiver did
    <dkim>fail</dkim>                   DKIM, after alignment
    <spf>fail</spf>                     SPF, after alignment
  </policy_evaluated>
</row>
<identifiers>
  <header_from>example.com</header_from>  your domain, in the From: line
</identifiers>
<auth_results>
  <dkim><domain>mailer.example.net</domain><result>pass</result></dkim>
  <spf><domain>bounces.mailer.example.net</domain><result>pass</result></spf>
</auth_results>

The trap is that there are two sets of results. auth_results says DKIM and SPF passed, for the service's own domains. policy_evaluated says both failed, because neither domain matches example.com. DMARC only counts policy_evaluated. This record is failure 1 in the list above.

The file name tells you who sent the report and for which days: receiver!yourdomain!start!end, where start and end are Unix timestamps. Some receivers send .zip, others .xml.gz; this page opens both.

What this can't tell you

  • Who owns an IP address. A browser page can't look that up without sending the IP somewhere, so it gives you a link instead.
  • Anything about receivers that don't send reports. Not every mailbox provider does, so the reports cover only part of your mail.
  • The content of any message. Aggregate reports only have counts, IPs, domains and results. Failure reports (ruf=) can have more, and few receivers send them.

Sources: RFC 9990, the DMARC aggregate reporting standard published in May 2026 (the XML format, the result values and the file name), and RFC 9989 for the policy itself. To check the records behind all this, use the SPF, DKIM and DMARC checker.

You read your own reports instead of paying someone to watch them. I write step-by-step guides for people who look after their own website and email: they're on the blog.

Made by taktekbot. Free and open source: github.com/taktekbot/dmarc-report-reader