Skip to content
Docs

Read aggregate and forensic DMARC reports for a sending domain, or upload your own.

Base URLhttps://api.emailit.com/v2AuthenticationErrorsRate limits

List aggregate reports

Returns the DMARC reports for a sending domain, newest first. Requires an API key with the full scope.

Emailit collects reports only for domains with DMARC reports turned on (dmarc_reports: true in Update a domain), which requires the Pro plan or higher. See DMARC reports.

The list includes forensic reports too. Pass type=aggregate to list only aggregate reports, or use List forensic reports for forensic details.

GET/domains/{id}/dmarc/reports

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name, for example acme.com.

Query parameters

typestring
aggregate or forensic.
statusstring
Processing status: pending, processed, failed or duplicate.
org_namestring
Exact name of the reporting organization, for example google.com.
fromstring
Only reports whose period starts on or after this date or date-time, for example 2026-09-01.
tostring
Only reports whose period starts on or before this date or date-time. A date without a time includes the whole day (UTC).
limitintegerdefault: 25
Reports per page, up to 100.
offsetintegerdefault: 0
Number of reports to skip.
matchstring

all (default) requires every filter. or matches any filter. See Filtering.

orderstring

Sort key for this list. See the sort keys below.

directionstring

asc or desc.

The generic key.condition=value filters also work on type, status, org_name and created_at; those are also the sort keys for order. See Filtering.

Returns

Returns data, an array of report objects, and meta with total, limit and offset.

idstring
Report ID, prefixed dmr_.
typestring | null
aggregate or forensic. null until an uploaded report is processed.
sourcestring
smtp for reports Emailit received at the domain’s reporting address, upload for reports you uploaded.
statusstring
pending, processed, failed (see error_message) or duplicate (the same report was already processed).
org_name, org_emailstring | null
The organization that sent the report and its contact address.
external_report_idstring | null
The reporter’s own report ID.
date_range_begin, date_range_endstring | null
The period the report covers, in UTC.
policy_domain, adkim, aspf, p, sp, pct, fostring | integer | null
The DMARC policy the reporter found for your domain: alignment modes (r or s), policy and subdomain policy (none, quarantine, reject), percentage and failure-reporting options.
original_filenamestring | null
File name of an uploaded report.
envelope_tostring | null
The reporting address the report was sent to.
created_at, updated_at, processed_atstring | null
Timestamps in UTC.

Returns 404 if the domain doesn’t exist in the workspace.

GET/domains/{id}/dmarc/reports
Terminal
curl -G https://api.emailit.com/v2/domains/acme.com/dmarc/reports \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -d type=aggregate \
  -d from=2026-09-01 \
  -d limit=50
JSON
{
  "data": [
    {
      "object": "dmarc_report",
      "id": "dmr_3Xu63kEs8KCiyOZ1TDgnttppitx",
      "type": "aggregate",
      "source": "smtp",
      "status": "processed",
      "org_name": "google.com",
      "org_email": "noreply-dmarc-support@google.com",
      "external_report_id": "4129847120347812934",
      "date_range_begin": "2026-09-29 00:00:00+00",
      "date_range_end": "2026-09-29 23:59:59+00",
      "policy_domain": "acme.com",
      "adkim": "r",
      "aspf": "r",
      "p": "none",
      "sp": "none",
      "pct": 100,
      "fo": null,
      "original_filename": null,
      "error_message": null,
      "envelope_to": "k2v9x4qa7m@dmarc.emailitmail.com",
      "created_at": "2026-09-30 04:12:09.214377+00",
      "updated_at": "2026-09-30 04:12:11.902154+00",
      "processed_at": "2026-09-30 04:12:11.902154+00"
    }
  ],
  "meta": { "total": 1, "limit": 50, "offset": 0 }
}

Retrieve a report

Retrieves one DMARC report. For an aggregate report, the response includes its records, one per sending source, sorted by message count. For a forensic report, it includes the failure sample in forensic. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher.

GET/domains/{id}/dmarc/reports/{report_id}

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.
report_idstringrequired
The report ID (dmr_…).

Query parameters

limitintegerdefault: 100
Records to return, up to 500. Aggregate reports only.
offsetintegerdefault: 0
Records to skip. Aggregate reports only.

Returns

Returns the report object (see List aggregate reports) plus:

recordsobject[]
Aggregate reports only. One entry per source IP and result combination. See the fields below.
metaobject
Aggregate reports only. total records, limit and offset.
forensicobject | null
Forensic reports only. The same fields as Retrieve a forensic report.

Each record has:

source_ipstring
IP address that sent the messages.
countinteger
Number of messages from this source with these results.
country_code, country_name, continent_code, asn, as_org, latitude, longitudestring | integer | number | null
Location and network of the source IP. null when the IP couldn’t be located.
dispositionstring
What the receiver did: none, quarantine or reject.
dkim, spfstring
DMARC-aligned results as evaluated by the receiver: pass or fail.
header_from, envelope_from, envelope_tostring | null
Identifiers from the report.
dkim_domain, dkim_selector, dkim_resultstring | null
The DKIM signature the receiver checked and its raw result.
spf_domain, spf_resultstring | null
The SPF domain the receiver checked and its raw result.
reason_type, reason_commentstring | null
Policy override reason, for example forwarded or mailing_list.

Returns 404 if the domain or the report doesn’t exist.

GET/domains/{id}/dmarc/reports/{report_id}
Terminal
curl https://api.emailit.com/v2/domains/acme.com/dmarc/reports/dmr_3Xu63kEs8KCiyOZ1TDgnttppitx \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "object": "dmarc_report",
  "id": "dmr_3Xu63kEs8KCiyOZ1TDgnttppitx",
  "type": "aggregate",
  "source": "smtp",
  "status": "processed",
  "org_name": "google.com",
  "org_email": "noreply-dmarc-support@google.com",
  "external_report_id": "4129847120347812934",
  "date_range_begin": "2026-09-29 00:00:00+00",
  "date_range_end": "2026-09-29 23:59:59+00",
  "policy_domain": "acme.com",
  "adkim": "r",
  "aspf": "r",
  "p": "none",
  "sp": "none",
  "pct": 100,
  "fo": null,
  "original_filename": null,
  "error_message": null,
  "envelope_to": "k2v9x4qa7m@dmarc.emailitmail.com",
  "created_at": "2026-09-30 04:12:09.214377+00",
  "updated_at": "2026-09-30 04:12:11.902154+00",
  "processed_at": "2026-09-30 04:12:11.902154+00",
  "records": [
    {
      "object": "dmarc_report_record",
      "source_ip": "198.51.100.24",
      "count": 1840,
      "country_code": "US",
      "country_name": "United States",
      "continent_code": "NA",
      "asn": 64500,
      "as_org": "Example Hosting",
      "latitude": 37.751,
      "longitude": -97.822,
      "disposition": "none",
      "dkim": "pass",
      "spf": "pass",
      "header_from": "acme.com",
      "envelope_from": "emailit.acme.com",
      "envelope_to": null,
      "dkim_domain": "acme.com",
      "dkim_selector": "emailit",
      "dkim_result": "pass",
      "spf_domain": "emailit.acme.com",
      "spf_result": "pass",
      "reason_type": null,
      "reason_comment": null
    },
    {
      "object": "dmarc_report_record",
      "source_ip": "203.0.113.77",
      "count": 12,
      "country_code": "NL",
      "country_name": "Netherlands",
      "continent_code": "EU",
      "asn": 64511,
      "as_org": "Example Networks",
      "latitude": 52.3824,
      "longitude": 4.8995,
      "disposition": "none",
      "dkim": "fail",
      "spf": "fail",
      "header_from": "acme.com",
      "envelope_from": "acme.com",
      "envelope_to": null,
      "dkim_domain": null,
      "dkim_selector": null,
      "dkim_result": null,
      "spf_domain": "acme.com",
      "spf_result": "softfail",
      "reason_type": null,
      "reason_comment": null
    }
  ],
  "meta": { "total": 2, "limit": 100, "offset": 0 }
}

Upload a report

Uploads a DMARC report you received elsewhere, for example from a mailbox you used before Emailit. Requires an API key with the full scope.

Emailit stores the file and processes it in the background: the response has status pending, and the report becomes processed, failed or duplicate (already imported) shortly after. Check it with Retrieve a report. Reports Emailit receives by email need DMARC reports turned on for the domain (Pro plan or higher); uploaded reports are processed either way.

POST/domains/{id}/dmarc/reports

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Body parameters

Send exactly one of content_base64 or content. The decoded report can be up to 10 MB.

content_base64string
The file, Base64-encoded. Use it for binary formats: aggregate reports as .xml, .xml.gz or .zip, and forensic reports as .eml (AFRF).
contentstring
The report as UTF-8 text, for example raw aggregate XML.
filenamestring
Original file name, stored as original_filename.

Returns

Returns 202 Accepted with the new report object. type is null until processing detects it.

Status When
400 Neither content_base64 nor content is set, or the value is empty.
404 The domain doesn’t exist in the workspace.
413 The decoded report is larger than 10 MB.
POST/domains/{id}/dmarc/reports
Terminal
curl -X POST https://api.emailit.com/v2/domains/acme.com/dmarc/reports \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{
    \"filename\": \"google-acme.com-2026-09-29.xml.gz\",
    \"content_base64\": \"$(base64 < 'google-acme.com-2026-09-29.xml.gz' | tr -d '\n')\"
  }"
JSON
{
  "object": "dmarc_report",
  "id": "dmr_3MjUXgcEBO0o7FkzeBdlrCY6NYk",
  "type": null,
  "source": "upload",
  "status": "pending",
  "org_name": null,
  "org_email": null,
  "external_report_id": null,
  "date_range_begin": null,
  "date_range_end": null,
  "policy_domain": null,
  "adkim": null,
  "aspf": null,
  "p": null,
  "sp": null,
  "pct": null,
  "fo": null,
  "original_filename": "google-acme.com-2026-09-29.xml.gz",
  "error_message": null,
  "envelope_to": null,
  "created_at": "2026-10-01 12:03:55.607+00",
  "updated_at": "2026-10-01 12:03:55.607+00",
  "processed_at": null
}

List forensic reports

Returns the processed forensic (RUF) reports for a domain, newest first. Each describes one message that failed DMARC. Headers are left out of the list; retrieve a forensic report to see them. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher. Few mailbox providers send forensic reports, and those that do may include personal data from the failed message.

GET/domains/{id}/dmarc/forensic

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Query parameters

fromstring
Only reports whose period starts on or after this date or date-time.
tostring
Only reports whose period starts on or before this date or date-time. A date without a time includes the whole day (UTC).
limitintegerdefault: 25
Reports per page, up to 100.
offsetintegerdefault: 0
Number of reports to skip.

The generic key.condition=value filters also work on org_name and created_at, with match, order and direction. See Filtering.

Returns

Returns data and meta (total, limit, offset). Each item has:

objectstring
dmarc_forensic_report.
id, report_idstring
The report ID (dmr_…).
arrival_datestring | null
When the failed message reached the receiver.
source_ipstring | null
IP address that sent the message.
country_code, country_name, continent_code, asn, as_org, latitude, longitudestring | integer | number | null
Location and network of the source IP.
auth_failurestring | null
What failed, for example dmarc, spf or dkim.
authentication_resultsstring | null
The receiver’s Authentication-Results header.
original_mail_from, original_rcpt_to, subjectstring | null
Envelope sender, recipient and subject of the failed message.
delivery_resultstring | null
What the receiver did, for example reject or delivered.
reported_domainstring | null
Your domain as named in the report.
created_atstring | null
When Emailit stored the report.
GET/domains/{id}/dmarc/forensic
Terminal
curl -G https://api.emailit.com/v2/domains/acme.com/dmarc/forensic \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -d from=2026-09-01
JSON
{
  "data": [
    {
      "object": "dmarc_forensic_report",
      "id": "dmr_3MjUXgcEBO0o7FkzeBdlrCY6NYk",
      "report_id": "dmr_3MjUXgcEBO0o7FkzeBdlrCY6NYk",
      "arrival_date": "2026-09-28 17:44:02+00",
      "source_ip": "203.0.113.77",
      "country_code": "NL",
      "country_name": "Netherlands",
      "continent_code": "EU",
      "asn": 64511,
      "as_org": "Example Networks",
      "latitude": 52.3824,
      "longitude": 4.8995,
      "auth_failure": "dmarc",
      "authentication_results": "mx.example.net; dmarc=fail (p=none) header.from=acme.com; spf=softfail smtp.mailfrom=acme.com; dkim=none",
      "original_mail_from": "billing@acme.com",
      "original_rcpt_to": "ada@example.net",
      "subject": "Your invoice is ready",
      "delivery_result": "delivered",
      "reported_domain": "acme.com",
      "created_at": "2026-09-28 18:02:16.448210+00"
    }
  ],
  "meta": { "total": 1, "limit": 25, "offset": 0 }
}

Retrieve a forensic report

Retrieves one forensic (RUF) report with the headers of the message that failed DMARC. Requires an API key with the full scope. Forensic reports can contain personal data, such as recipient addresses and subjects.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher.

GET/domains/{id}/dmarc/forensic/{report_id}

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.
report_idstringrequired
The report ID (dmr_…) of a forensic report.

Returns

Returns the forensic report with the fields described in List forensic reports, plus:

headersstring | null
The original message headers included in the report, as raw text.

Returns 404 if the domain doesn’t exist, the report doesn’t exist, or it isn’t a processed forensic report.

GET/domains/{id}/dmarc/forensic/{report_id}
Terminal
curl https://api.emailit.com/v2/domains/acme.com/dmarc/forensic/dmr_3MjUXgcEBO0o7FkzeBdlrCY6NYk \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "object": "dmarc_forensic_report",
  "id": "dmr_3MjUXgcEBO0o7FkzeBdlrCY6NYk",
  "report_id": "dmr_3MjUXgcEBO0o7FkzeBdlrCY6NYk",
  "arrival_date": "2026-09-28 17:44:02+00",
  "source_ip": "203.0.113.77",
  "country_code": "NL",
  "country_name": "Netherlands",
  "continent_code": "EU",
  "asn": 64511,
  "as_org": "Example Networks",
  "latitude": 52.3824,
  "longitude": 4.8995,
  "auth_failure": "dmarc",
  "authentication_results": "mx.example.net; dmarc=fail (p=none) header.from=acme.com; spf=softfail smtp.mailfrom=acme.com; dkim=none",
  "original_mail_from": "billing@acme.com",
  "original_rcpt_to": "ada@example.net",
  "subject": "Your invoice is ready",
  "delivery_result": "delivered",
  "reported_domain": "acme.com",
  "headers": "From: Acme Billing <billing@acme.com>\r\nTo: ada@example.net\r\nSubject: Your invoice is ready\r\nDate: Mon, 28 Sep 2026 17:43:58 +0000\r\nMessage-ID: <20260928174358.4f1c@mail.acme.com>",
  "created_at": "2026-09-28 18:02:16.448210+00"
}

Retrieve statistics

Summarizes the aggregate DMARC reports of a domain over a date range: how much mail receivers saw from your domain, how much passed, and where it came from. This is the data behind the Overview tab under Email APIDMARC reports. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on (dmarc_reports: true in Update a domain), which requires the Pro plan or higher.

GET/domains/{id}/dmarc/stats

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Query parameters

fromstring
Only count report periods that start on or after this date or date-time, for example 2026-09-01. Without it, all reports are counted.
tostring
Only count report periods that start on or before this date or date-time. A date without a time includes the whole day (UTC).

Returns

Returns data with these fields. A message counts as passing when its DMARC-aligned DKIM or SPF result is pass.

total_volumeinteger
Messages reported.
pass_volume, fail_volumeinteger
Messages that passed and failed.
pass_ratenumber
Percentage of messages that passed, rounded to two decimals. 0 when there’s no volume.
report_countinteger
Processed reports in the range, aggregate and forensic.
dispositionsobject[]
Volume per receiver action: disposition (none, quarantine, reject) and volume.
dkim, spfobject[]
Volume per aligned result: result (pass or fail) and volume.
dailyobject[]
One entry per day (date as YYYY-MM-DD, UTC) with volume, pass_volume and fail_volume.
daily_dispositions, daily_dkim, daily_spfobject[]
The same breakdowns per day: date, disposition or result, and volume.
top_countriesobject[]
Up to 10 countries by volume: country_code, country_name, volume, pass_volume, fail_volume.
top_asnsobject[]
Up to 10 networks by volume: asn, as_org, volume, pass_volume, fail_volume.
unknown_geo_volumeinteger
Messages from IP addresses that couldn’t be located.

Returns 404 if the domain doesn’t exist in the workspace.

GET/domains/{id}/dmarc/stats
Terminal
curl -G https://api.emailit.com/v2/domains/acme.com/dmarc/stats \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -d from=2026-09-28 \
  -d to=2026-09-29
JSON
{
  "data": {
    "total_volume": 3712,
    "pass_volume": 3688,
    "fail_volume": 24,
    "pass_rate": 99.35,
    "report_count": 6,
    "dispositions": [
      { "disposition": "none", "volume": 3712 }
    ],
    "dkim": [
      { "result": "pass", "volume": 3680 },
      { "result": "fail", "volume": 32 }
    ],
    "spf": [
      { "result": "pass", "volume": 3676 },
      { "result": "fail", "volume": 36 }
    ],
    "daily": [
      { "date": "2026-09-28", "volume": 1860, "pass_volume": 1848, "fail_volume": 12 },
      { "date": "2026-09-29", "volume": 1852, "pass_volume": 1840, "fail_volume": 12 }
    ],
    "daily_dispositions": [
      { "date": "2026-09-28", "disposition": "none", "volume": 1860 },
      { "date": "2026-09-29", "disposition": "none", "volume": 1852 }
    ],
    "daily_dkim": [
      { "date": "2026-09-28", "result": "pass", "volume": 1844 },
      { "date": "2026-09-28", "result": "fail", "volume": 16 },
      { "date": "2026-09-29", "result": "pass", "volume": 1836 },
      { "date": "2026-09-29", "result": "fail", "volume": 16 }
    ],
    "daily_spf": [
      { "date": "2026-09-28", "result": "pass", "volume": 1842 },
      { "date": "2026-09-28", "result": "fail", "volume": 18 },
      { "date": "2026-09-29", "result": "pass", "volume": 1834 },
      { "date": "2026-09-29", "result": "fail", "volume": 18 }
    ],
    "top_countries": [
      { "country_code": "US", "country_name": "United States", "volume": 3688, "pass_volume": 3688, "fail_volume": 0 },
      { "country_code": "NL", "country_name": "Netherlands", "volume": 24, "pass_volume": 0, "fail_volume": 24 }
    ],
    "top_asns": [
      { "asn": 64500, "as_org": "Example Hosting", "volume": 3688, "pass_volume": 3688, "fail_volume": 0 },
      { "asn": 64511, "as_org": "Example Networks", "volume": 24, "pass_volume": 0, "fail_volume": 24 }
    ],
    "unknown_geo_volume": 0
  }
}

List sending sources

Groups a domain’s aggregate DMARC data by source IP address, highest volume first. Use it to spot servers that send as your domain but fail SPF and DKIM. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher.

GET/domains/{id}/dmarc/sources

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Query parameters

fromstring
Only count report periods that start on or after this date or date-time.
tostring
Only count report periods that start on or before this date or date-time. A date without a time includes the whole day (UTC).
limitintegerdefault: 50
Sources per page, up to 200.
offsetintegerdefault: 0
Number of sources to skip.

Returns

Returns data and meta (limit, offset). The response has no total; request the next page until data has fewer items than limit. Each source has:

source_ipstring
The sending IP address.
country_code, country_namestring | null
Where the IP is located.
asn, as_orginteger | string | null
The network the IP belongs to.
volumeinteger
Messages reported from this IP.
pass_volume, fail_volumeinteger
Messages that passed DMARC-aligned DKIM or SPF, and messages that failed both.

Returns 404 if the domain doesn’t exist in the workspace.

GET/domains/{id}/dmarc/sources
Terminal
curl -G https://api.emailit.com/v2/domains/acme.com/dmarc/sources \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -d from=2026-09-01
JSON
{
  "data": [
    {
      "source_ip": "198.51.100.24",
      "country_code": "US",
      "country_name": "United States",
      "asn": 64500,
      "as_org": "Example Hosting",
      "volume": 3688,
      "pass_volume": 3688,
      "fail_volume": 0
    },
    {
      "source_ip": "203.0.113.77",
      "country_code": "NL",
      "country_name": "Netherlands",
      "asn": 64511,
      "as_org": "Example Networks",
      "volume": 24,
      "pass_volume": 0,
      "fail_volume": 24
    }
  ],
  "meta": { "limit": 50, "offset": 0 }
}

List countries

Groups a domain’s aggregate DMARC data by the country of the sending IP, highest volume first. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher.

GET/domains/{id}/dmarc/countries

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Query parameters

fromstring
Only count report periods that start on or after this date or date-time.
tostring
Only count report periods that start on or before this date or date-time. A date without a time includes the whole day (UTC).
limitintegerdefault: 50
Countries per page, up to 200.
offsetintegerdefault: 0
Number of countries to skip.

Returns

Returns data and meta (limit, offset). Each country has:

country_codestring | null
ISO 3166-1 alpha-2 code. null groups IP addresses that couldn’t be located.
country_namestring | null
Country name.
continent_codestring | null
Continent code, for example EU.
volumeinteger
Messages reported from this country.
pass_volume, fail_volumeinteger
Messages that passed DMARC-aligned DKIM or SPF, and messages that failed both.

Returns 404 if the domain doesn’t exist in the workspace.

GET/domains/{id}/dmarc/countries
Terminal
curl -G https://api.emailit.com/v2/domains/acme.com/dmarc/countries \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -d from=2026-09-01
JSON
{
  "data": [
    {
      "country_code": "US",
      "country_name": "United States",
      "continent_code": "NA",
      "volume": 3688,
      "pass_volume": 3688,
      "fail_volume": 0
    },
    {
      "country_code": "NL",
      "country_name": "Netherlands",
      "continent_code": "EU",
      "volume": 24,
      "pass_volume": 0,
      "fail_volume": 24
    }
  ],
  "meta": { "limit": 50, "offset": 0 }
}

List networks (ASNs)

Groups a domain’s aggregate DMARC data by the autonomous system (ASN) of the sending IP, highest volume first. A network usually maps to a hosting provider or email service, which makes it easier to recognize legitimate senders. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher.

GET/domains/{id}/dmarc/asns

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Query parameters

fromstring
Only count report periods that start on or after this date or date-time.
tostring
Only count report periods that start on or before this date or date-time. A date without a time includes the whole day (UTC).
limitintegerdefault: 50
Networks per page, up to 200.
offsetintegerdefault: 0
Number of networks to skip.

Returns

Returns data and meta (limit, offset). Each network has:

asninteger | null
Autonomous system number. null groups IP addresses that couldn’t be looked up.
as_orgstring | null
Name of the organization that operates the network.
volumeinteger
Messages reported from this network.
pass_volume, fail_volumeinteger
Messages that passed DMARC-aligned DKIM or SPF, and messages that failed both.

Returns 404 if the domain doesn’t exist in the workspace.

GET/domains/{id}/dmarc/asns
Terminal
curl -G https://api.emailit.com/v2/domains/acme.com/dmarc/asns \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -d from=2026-09-01
JSON
{
  "data": [
    {
      "asn": 64500,
      "as_org": "Example Hosting",
      "volume": 3688,
      "pass_volume": 3688,
      "fail_volume": 0
    },
    {
      "asn": 64511,
      "as_org": "Example Networks",
      "volume": 24,
      "pass_volume": 0,
      "fail_volume": 24
    }
  ],
  "meta": { "limit": 50, "offset": 0 }
}

List reporters

Lists the organizations that sent processed aggregate reports for a domain, most reports first. Requires an API key with the full scope.

Reports arrive only for domains with DMARC reports turned on, which requires the Pro plan or higher.

GET/domains/{id}/dmarc/reporters

Path parameters

idstringrequired
The domain ID (dom_…) or the domain name.

Query parameters

fromstring
Only count reports whose period starts on or after this date or date-time.
tostring
Only count reports whose period starts on or before this date or date-time. A date without a time includes the whole day (UTC).
limitintegerdefault: 50
Reporters per page, up to 200.
offsetintegerdefault: 0
Number of reporters to skip.

Returns

Returns data and meta (limit, offset). Each reporter has:

org_namestring | null
Name of the reporting organization, for example google.com. Pass it as org_name to List aggregate reports to see its reports.
org_emailstring | null
The reporter’s contact address.
report_countinteger
Number of processed aggregate reports from this organization.

Returns 404 if the domain doesn’t exist in the workspace.

GET/domains/{id}/dmarc/reporters
Terminal
curl https://api.emailit.com/v2/domains/acme.com/dmarc/reporters \
  -H "Authorization: Bearer $EMAILIT_API_KEY"
JSON
{
  "data": [
    { "org_name": "google.com", "org_email": "noreply-dmarc-support@google.com", "report_count": 30 },
    { "org_name": "Enterprise Outlook", "org_email": "dmarcreport@microsoft.com", "report_count": 28 },
    { "org_name": "Yahoo", "org_email": "dmarchelp@yahooinc.com", "report_count": 14 }
  ],
  "meta": { "limit": 50, "offset": 0 }
}

Was this page helpful?

Thanks for the feedback.

Thanks, we read every message.