Free DMARC report analyzer

Paste or drop the aggregate report a receiver emailed you and read it as a table: which sources sent email as your domain, how many messages, whether SPF and DKIM aligned, and what the receiver did. The report is parsed in your browser and never sent to us.

Open the attachment in a text editor and paste everything from the first line to the closing feedback tag.

.xml, .xml.gz or .zip, as the receiver sent it, up to 10 MB. It is read on this device and never uploaded.

Reading the table

What each column means.

Source IP
The server that delivered the messages, as the receiver saw it. The report does not name the service behind it; that is the sender to identify.
Messages
How many messages from that source the receiver counted in the period. One row is one source, one From domain and one result.
From domain
The domain in the From header people see, which is the domain DMARC protects.
SPF / DKIM
Whether each passed and aligned with the From domain. DMARC passes when either one does. A raw pass for another domain does not count, which is why the authentication column is shown too.
Disposition
What the receiver did under your published policy: none, quarantine or reject. A reason appears when the receiver overrode the policy, for example for forwarded mail.

The guide to DMARC reports reads Google’s example report element by element.

After one report

This is one report from one receiver for one day.

Every receiver that handles your email sends its own report, daily. DemiSignal paid plans give you a private reporting address, read every report as it arrives, keep the history per source and alert you when your records change, so you know when it is safe to enforce. Monitoring starts on the Starter plan.

See plans and pricing →

Questions, answered

Before you paste.

Does the file leave my browser?

No. The report is read by the script on this page, on your device, and nothing is uploaded: the page makes no network request while it parses. Close the tab and the report is gone. Paid plans work the other way round: receivers send reports to a private address and the reading is done for you.

Why does my report show a sender I do not recognise?

Forwarding, mailing lists and forgotten tools all appear as sources you did not expect, and so does abuse. A source that passes neither SPF nor DKIM is a sender to identify first: check whether a service you use sends from that address before treating it as an attacker.

Can I analyse many reports at once?

Not here. This tool reads one report at a time, and a domain with any volume receives a report from every receiver every day. Reading them all, keeping the history and alerting you when something changes is what the paid plans do.

Which files does it read?

The .xml, .xml.gz or .zip attachment exactly as a receiver emailed it, or the XML pasted out of it, up to 10 MB. Failure (RUF) reports are a different format and are not read here.

Related tools

No report yet? Start with the record.