Reading your DMARC reports
Once you publish a DMARC record with a rua= reporting address, mailbox providers send you aggregate reports - XML files summarising who sent mail using your domain and whether it passed SPF and DKIM. These reports are how you safely tighten your DMARC policy.
What the reports tell you:
- The sending IP addresses and how many messages each sent as your domain.
- Whether those messages passed or failed SPF and DKIM, and whether they aligned with your domain.
- This reveals both your legitimate senders (your hosting, your marketing platform) and any unauthorised or spoofing sources.
The raw XML is hard to read by eye. Use a DMARC report analyser (many offer a free tier) - you point your rua address to their service, and they turn the XML into readable dashboards.
How to act on them:
- Confirm all your genuine senders pass and align. If one fails, fix its SPF/DKIM before tightening policy.
- Once everything legitimate passes, move your policy from
p=nonetoquarantine, thenreject. - Watch for unexpected sources - a sign someone is spoofing your domain, which DMARC enforcement will then block.
Reviewing reports for a few weeks before enforcing protects your own mail from being blocked. Need help interpreting a report or choosing when to enforce? Our team can assist - support@dirhamaday.ae.
Still need a hand? Our UAE-based team is here 24/7.