Skip to main content

DMARC Analyzer

Use our DMARC analyzer to make DMARC aggregate XML reports human readable by parsing and aggregating them by IP address into readable reports. Upload XML, ZIP, or GZ files to analyze SPF/DKIM authentication rates, message volumes, and policy actions.

Free & PrivateBrowser-BasedXML/ZIP/GZ Support

Upload DMARC Report

Drag & drop an XML, .gz, or ZIP (containing XML) — or tap to browse. Supports DMARC aggregate reports from Gmail, Yahoo!, Outlook, and other major email providers.

XMLZIPGZ
We don’t upload your file to a server — parsing runs in your browser.

About DMARC Report Analyzer

This tool will make DMARC Aggregate XML reports human readable by parsing and aggregating them by IP address into readable reports. DMARC Aggregate XML reports are sent by mail receivers (like Gmail, Yahoo!, & more) and include valuable data such as message volumes seen, SPF/DKIM Authentication rates, actions taken on the message (quarantine/reject), and more.

The un-parsed reports themselves are hard to decipher and contain non-aggregated data. To receive and view DMARC reports you need to setup a DMARC Record for your domain. Our free tool helps you analyze these reports to understand your email security posture and improve deliverability.

What is a DMARC aggregate report?

A daily XML summary from receivers showing which sources sent mail for your domain and whether SPF/DKIM aligned under your DMARC policy. These reports help identify unauthorized senders and authentication issues.

Why analyze these reports?

Identify unauthorized senders, fix misconfigurations, and safely roll out stricter enforcement to protect your brand and deliverability. Regular analysis helps maintain email security compliance.

How to get started

First, validate your DMARC record. Need a record? Use theDMARC record generator, or readwhat DMARC is.

Key Features of Our DMARC Report Analyzer

Privacy-First Analysis

All parsing happens locally in your browser. We never upload your DMARC reports to our servers, ensuring complete privacy and security.

Multiple File Format Support

Upload raw XML files, compressed .xml.gz files, or ZIP archives containing multiple reports for batch analysis.

Comprehensive Authentication Analysis

Detailed breakdown of SPF and DKIM authentication results, policy alignment, and actionable recommendations for improvement.

Email Security Health Scoring

Get an overall health score based on authentication rates, policy strength, and coverage to track your progress over time.

How to Get DMARC Aggregate Reports

Mail receivers only send you reports if your DMARC record asks for them. Getting reports takes three steps:

  1. Publish a DMARC record with a rua address. Use the DMARC record generator to create one, e.g. v=DMARC1; p=none; rua=mailto:[email protected]
  2. Wait for receivers to send reports. Gmail, Microsoft, Yahoo!, and most large providers send one aggregate report per day, usually as a compressed XML attachment (.xml.gz or .zip), starting within 24–48 hours of publishing your record.
  3. Download and upload the attachment here. No need to extract it first — the analyzer reads XML, GZ, and ZIP directly, entirely in your browser.

How to Read a DMARC Aggregate Report

Every aggregate report contains the same building blocks. These are the fields that matter and what to do with them:

FieldMeaning
org_nameThe receiver that generated the report (e.g. google.com)
source_ipThe server that sent mail claiming to be your domain
countHow many messages came from that source in the period
dispositionWhat the receiver did: none, quarantine, or reject
dkim / spfWhether each authentication check passed with alignment
header_fromThe visible From domain being evaluated

Two patterns matter most. Known providers failing authentication means a misconfiguration — fix your SPF record or DKIM signing for that service. Unknown IPs sending significant volume means someone is spoofing your domain — exactly what a stricter policy (p=quarantine or p=reject) will stop.

Frequently Asked Questions

Do you upload my DMARC reports to a server?

No. All parsing happens locally in your browser for complete privacy and security.

Which file formats are supported?

Raw XML (.xml), compressed XML (.xml.gz), and ZIP archives that contain XML or GZ files.

How do I start receiving DMARC reports?

Publish a DMARC record that includes a rua=mailto: address. Receivers like Gmail and Microsoft will begin sending daily aggregate reports to that address within 24-48 hours.

Who sends DMARC aggregate reports?

Receiving mail providers that support DMARC reporting — including Gmail, Microsoft (Outlook/Office 365), Yahoo!, and many others — each send one report per day covering the mail they saw from your domain.

What should my DMARC policy be?

Start with monitoring (p=none), then move to p=quarantine and finally p=reject once all legitimate senders pass SPF or DKIM authentication.

How often should I analyze DMARC reports?

Weekly analysis is recommended to monitor authentication trends and quickly identify any new issues or unauthorized senders.

What do the authentication percentages mean?

Higher percentages indicate better email security. Aim for 95%+ SPF and DKIM pass rates before implementing strict policies.

Understanding DMARC Report Data

DMARC aggregate reports contain valuable information about your email security posture. Our analyzer helps you understand:

Authentication Results

  • • SPF (Sender Policy Framework) authentication status
  • • DKIM (DomainKeys Identified Mail) signature verification
  • • Policy alignment and enforcement actions

Traffic Analysis

  • • Message volumes from different sending sources
  • • IP addresses and domains sending on your behalf
  • • Geographic and organizational distribution