Reviewed by: QuickDMARC Security Team · Email Authentication Specialists ·

DMARC Reports

DMARC reports are feedback from mailbox providers about mail using your domain: aggregate XML summaries (RUA) and optional failure samples (RUF).

Aggregate vs forensic

Aggregate reports summarize volumes, IPs, and SPF/DKIM/DMARC results over a period. Forensic reports may include message samples for failures—and raise privacy considerations.

FieldValue
RUAAggregate XML via rua=mailto:
RUFFailure reports via ruf=mailto:

What to look for first

Unknown source IPs, high fail volumes on marketing ESPs, SPF PermError clusters, and domains with p=none that never progress.

Operational workflow

Ingest reports daily, classify sources as authorized / unauthorized / investigate, fix alignment, then raise policy.

How QuickDMARC helps

QuickDMARC parses aggregate reports into dashboards so you do not manually decode compressed XML from dozens of reporters.

Frequently asked questions

Why am I not receiving reports?

Confirm rua uses mailto:, the report URI domain authorizes your domain (external destination verification), and DNS has propagated.

Are forensic reports required?

No. Many organizations rely primarily on aggregate reports.

Can I analyze XML myself?

Yes—or use the DMARC report analyzer / QuickDMARC monitoring.

Related resources