DMARC Reports
DMARC reports are feedback from mailbox providers about mail using your domain: aggregate XML summaries (RUA) and optional failure samples (RUF).
Aggregate vs forensic
Aggregate reports summarize volumes, IPs, and SPF/DKIM/DMARC results over a period. Forensic reports may include message samples for failures—and raise privacy considerations.
| Field | Value |
|---|---|
| RUA | Aggregate XML via rua=mailto: |
| RUF | Failure reports via ruf=mailto: |
What to look for first
Unknown source IPs, high fail volumes on marketing ESPs, SPF PermError clusters, and domains with p=none that never progress.
Operational workflow
Ingest reports daily, classify sources as authorized / unauthorized / investigate, fix alignment, then raise policy.
How QuickDMARC helps
QuickDMARC parses aggregate reports into dashboards so you do not manually decode compressed XML from dozens of reporters.
Frequently asked questions
Why am I not receiving reports?
Confirm rua uses mailto:, the report URI domain authorizes your domain (external destination verification), and DNS has propagated.
Are forensic reports required?
No. Many organizations rely primarily on aggregate reports.
Can I analyze XML myself?
Yes—or use the DMARC report analyzer / QuickDMARC monitoring.