Overview
DMARC reports
Collect DMARC aggregate and forensic reports from mailbox providers in a hosted Emailit mailbox and see who sends as your domain and whether their mail passes.
DMARC reports tell you which servers send email using your domain and whether that mail passes authentication. Emailit gives each sending domain a hosted reporting address, processes the reports mailbox providers send there, and shows the results in the dashboard. Use them to find services you forgot to authenticate and to move your DMARC policy safely toward reject.
What DMARC reports are
When your domain publishes a DMARC record with reporting addresses, mailbox providers such as Google, Microsoft and Yahoo send you two kinds of reports:
| Report | DMARC tag | What it contains | How often |
|---|---|---|---|
| Aggregate (RUA) | rua= |
A summary of all mail the provider saw from your domain: source IP addresses, message counts, SPF and DKIM results, and what the provider did with the mail. No message content. | Usually once a day per provider |
| Forensic (RUF) | ruf= |
Details of individual messages that failed DMARC, such as headers, subject and addresses. | Per failure. Few providers send them. |
Aggregate reports are XML files that are hard to read by hand. Emailit parses them for you, adds the country and network of each source IP, and removes duplicates.
How it works
- Turn on reports for a domain. Emailit creates a reporting address for it, in the form
<token>@dmarc.emailitmail.com. - Add the address to your DMARC record as both
ruaandruf. If you already have a DMARC record, add the address to it. - Mailbox providers send reports to the address, usually starting within 24 to 48 hours.
- Emailit processes each report and adds it to the domain’s DMARC dashboard.
You can also upload reports you received elsewhere. Set up DMARC reports walks through every step.
What you can see
Go to Email APIDMARC reports. The list shows each sending domain with its Status, Reporting address and a Reports switch. Select a domain to open its reports, then pick a range of 7, 30 or 90 days.
| Tab | What it shows |
|---|---|
| Overview | Total volume, Pass rate, Fail volume and number of Reports, a Daily volume chart of passing and failing mail, Dispositions, and the top countries and networks. |
| Sources | Every IP address that sent as your domain, with its country, network (ASN) and pass and fail volume. |
| Countries | Volume by country and continent. |
| ASNs | Volume by network operator, such as Google or Amazon. |
| Reports | Each report with its Reporter, Type, Status, Source and Date range. Open one to see its records. |
| Forensic | Individual failure reports with Arrival, Source IP, Auth failure, Reported domain and Subject. |
Read DMARC reports explains what each number means and what to do about it.
Privacy of forensic reports
Forensic reports can contain personal data: recipient and sender addresses, subjects and message headers. Emailit stores them in your workspace and shows them only to its members. If you don’t want to receive them, leave the ruf tag out of your DMARC record and keep only rua.
Availability
DMARC reports are included with Pro, Business and Custom plans. On Pay as you go, the DMARC reports page offers an upgrade.
| Pay as you go | Pro | Business | Custom | |
|---|---|---|---|---|
| DMARC reports | — | Included | Included | Included |
Reports are also available through the DMARC reports API, including uploads, statistics, sources, countries and networks.