Definition
DMARC reporting is a feedback mechanism defined in the DMARC specification (RFC 7489) that provides domain owners with visibility into how their email is being authenticated and handled by receiving mail servers. DMARC reports come in two types: aggregate reports (RUA) and forensic reports (RUF). Aggregate reports provide statistical summaries of authentication results over a period (typically 24 hours), while forensic reports provide detailed information about specific individual messages that failed authentication.
Aggregate DMARC reports contain data organised by sending IP address, including: the total volume of messages from each IP, the SPF and DKIM authentication results (pass, fail, or temporary error), the DMARC disposition applied (none, quarantine, or reject), and the identifier alignment results (SPF and DKIM domain alignment). These reports do not contain personal data or message content, making them safe for automated processing. Aggregate reports are sent as XML attachments in compressed format, typically generated once per day by participating receiving mail servers. Major providers including Gmail, Outlook, and Yahoo send aggregate reports.
Forensic DMARC reports (RUF) provide detailed information about individual messages that failed DMARC authentication. These reports can include the full email headers and, in some configurations, the entire message body. Because of the privacy implications, forensic reports are less commonly requested and many mailbox providers limit or decline to send them due to data protection concerns. Forensic reports are most useful for investigating specific instances of suspected spoofing or phishing, or for detailed troubleshooting of authentication failures for specific legitimate messages.
Best Practices
Start with aggregate report collection (RUA) before configuring any DMARC enforcement policy. Aggregate reports provide the baseline data needed to understand your email sending landscape: which IPs are sending email for your domain, whether SPF and DKIM are correctly configured, and whether any unauthorised senders are using your domain. Without this data, setting a DMARC policy risks blocking legitimate email.
Use a DMARC report analysis tool rather than trying to parse raw XML reports. Raw DMARC aggregate reports are machine-generated XML files that are difficult to analyse manually. Numerous commercial and open-source tools ingest these reports and provide dashboards showing: sending sources, authentication pass/fail rates, geography of sending servers, and trend analysis over time.
Set up DMARC reporting for all domains, not just your primary sending domain. Spoofers often target less-protected subdomains or brand-alike domains. Configure DMARC with reporting (p=none) on all domains and subdomains your organisation owns. Review the reports to identify any domains sending email with your brand in the From address. Add unauthorised domains to your monitoring scope.
Review DMARC aggregate reports at least weekly during initial deployment and monthly thereafter. The first 30-90 days of report collection will reveal the full picture of your email ecosystem. After the initial period, monthly reviews catch new senders, configuration changes, and developing issues. Set up alerts for specific report anomalies: a sudden increase in volume from an unrecognised IP, a spike in SPF failures, or new geographic sending locations.
Archive DMARC reports for at least 12 months for audit and compliance purposes. DMARC reports provide an audit trail of email authentication activity that may be needed for incident investigations, compliance audits, or legal proceedings. Ensure your report storage complies with your data retention policy and can produce historical data on request.
Related Glossary Terms
DMARC Alignment
DMARC identifier alignment determines whether the domain in the From header matches the domains used in SPF and DKIM authentication. Strict or relaxed.
DMARC Policy Tags
DMARC DNS record tags including v, p, sp, rua, ruf, pct, adkim, aspf, fo, rf, and ri control authentication policy, reporting, and alignment enforcement.
Email Attribution Window
Email attribution window defines how far back conversions are credited to an email send or campaign. Typical windows are 7 days for promotional, 30 days for transactional, and 90 days for B2B nurture.
Email Bandwidth
Email sending bandwidth and throughput refer to the rate at which emails can be delivered, typically 100-500 emails/second per IP. Bandwidth planning ensures campaigns complete within desired delivery windows.
Email BIMI VMC
BIMI Verified Mark Certificate (VMC) certifies brand logo ownership for display in supporting email clients. VMCs cost £1,500-2,000+ per year per logo and require DMARC reject or quarantine policy plus SVG logo format.
Email Blacklist
An email blacklist (DNSBL) is a real-time database of IP addresses or domains known for sending spam or unwanted email.
Frequently Asked Questions
RUA (Aggregate Report URI) receives aggregate reports: statistical summaries of authentication results by IP address over a 24-hour period. RUF (Forensic Report URI) receives forensic reports: detailed information about individual messages that failed DMARC, potentially including full email content. RUA is widely supported and privacy-safe; RUF support is more limited due to data protection concerns.
Publish a DMARC record (TXT record at `_dmarc.yourdomain.com`) that includes RUA and optionally RUF directives pointing to an email address or HTTPS endpoint capable of receiving and processing the reports. For example: `rua=mailto:dmarc-reports@yourdomain.com`. Use a DMARC report processing service or set up inbound email processing to handle the reports.
Each aggregate report contains: reporting organisation identifier, report period (start and end timestamps), policy published, and a series of records keyed by sending IP address. Each record includes: volume count, disposition (none/quarantine/reject), SPF authentication result, DKIM authentication result, identifier alignment results, and the organisational domain used in the evaluation.
DMARC reports reveal your complete email sending ecosystem. Without reviewing reports, you may not know about all legitimate services that send email for your domain. Setting a reject policy before confirming that all legitimate senders are correctly authenticated will cause those services' emails to be rejected, resulting in business disruption.
Reports are generated and sent by receiving servers on their own schedule, typically once per day. It may take 24-72 hours after publishing a DMARC record before the first reports arrive. Major providers like Gmail and Outlook report regularly; smaller providers may not report at all. Not participating in DMARC reporting does not mean the provider is not evaluating DMARC.