Guide
Read DMARC reports
Understand pass rate, alignment and dispositions in DMARC reports, identify unknown senders, and move your policy from none to quarantine to reject safely.
This guide explains the numbers on the DMARC reports pages, how to tell your own services apart from unknown senders, and how to use the data to move your domain to an enforcing DMARC policy without blocking your own mail.
Overview metrics
Open Email APIDMARC reports, select a domain and choose 7, 30 or 90 days.
| Metric | What it means |
|---|---|
| Total volume | Messages that mailbox providers reported seeing from your domain in the period. |
| Pass rate | The share of that volume that passed DMARC: DKIM or SPF passed and aligned with your From domain. |
| Fail volume | Messages where neither DKIM nor SPF passed with alignment. |
| Reports | How many reports Emailit processed for the period. |
| Daily volume | Passing and failing mail per day. A sudden spike in failures can mean spoofing or a newly added service. |
| Dispositions | What providers did with the mail, based on your policy. |
The overview also lists the top countries and networks (ASNs). Messages from IP addresses Emailit can’t place are counted separately, such as “120 messages from unmapped IPs”.
Dispositions
| Disposition | Meaning |
|---|---|
none |
Delivered as normal. This is what happens to failing mail while your policy is p=none. |
quarantine |
Sent to spam or quarantine because it failed and your policy is p=quarantine. |
reject |
Refused because it failed and your policy is p=reject. |
Providers may still apply their own filtering to mail that passes.
Alignment
DMARC doesn’t just check that SPF or DKIM pass. It checks that the domain they verified matches the From domain. Report records show the DMARC-evaluated results, and the API returns the raw checks behind them:
| Field | What it tells you |
|---|---|
| DKIM and SPF | The DMARC-evaluated results, pass or fail, with alignment taken into account. Shown in the dashboard. |
dkim_domain, dkim_selector, dkim_result |
Which domain signed the message and whether the signature verified. In the API’s report records. |
spf_domain, spf_result |
Which return-path domain SPF checked and whether it passed. In the API’s report records. |
| Header from | The From domain the message claimed. |
Mail sent through Emailit should show DKIM pass with domain acme.com and selector emailit, and SPF pass for emailit.acme.com. DMARC only needs one of the two to pass with alignment.
It’s normal to see some mail where SPF fails but DKIM passes. Forwarding and mailing lists change the return path, which breaks SPF, while the DKIM signature survives.
Identify your senders
Open the Sources tab. Each row is an IP address that sent mail as your domain, with its country, network and pass and fail volume. Sort by Fail volume and work down the list. For each source, decide which group it falls into.
Services you use that pass. Emailit, your company mailbox provider such as Google Workspace or Microsoft 365, and other tools that you’ve set up with SPF or DKIM. Nothing to do.
Services you use that fail. A CRM, help desk, billing tool or website that sends as your domain without authentication. The network name usually gives it away, for example a cloud provider or the vendor’s own ASN. Fix each one:
- If the service supports DKIM for your domain, publish the record it gives you.
- If it only supports SPF, add its
include:to your root domain’s SPF record, or have it send from a subdomain. - If you can, move that mail to Emailit, which is already authenticated.
Mail you don’t recognize. Sources in unexpected countries or networks, often with low volume and 100% failure, are usually spoofing: someone sending as your domain. Moving to p=quarantine or p=reject is how you stop them.
The Countries and ASNs tabs group the same data by location and network operator, which helps when one service uses many IP addresses.
Reports and forensic tabs
The Reports tab lists every report, with the provider that sent it (the Reporter), its Status and Date range. Open a report to see when it was received and processed, and every record in it: Source IP, Count, Country, ASN, Disposition, DKIM, SPF and Header from.
The Forensic tab lists individual failures, when providers send them. Each one shows the source, the authentication results, the original sender and recipient, the subject and the headers. Use them to track down a specific failing message. They may contain personal data, so share them carefully.
Move to enforcement
Use your reports to tighten your policy in stages. Wait at each stage until the reports look right.
-
Start with
p=none. Collect reports for at least two to four weeks so you see every service, including ones that send only monthly, such as invoices.v=DMARC1; p=none; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; -
Fix every legitimate source. Continue until all the services you use pass and the remaining failures are mail you don’t recognize.
-
Quarantine a share of failing mail. Switch to
p=quarantinewithpctto apply it to part of the failing mail first, then raisepctto 100 over a week or two.v=DMARC1; p=quarantine; pct=25; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; -
Reject. When quarantine has run at 100% without your own mail showing up under Dispositions as
quarantine, switch top=reject.v=DMARC1; p=reject; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; -
Keep watching. Leave the
ruaaddress in place. A new tool that starts sending as your domain will show up as failing mail, and withp=rejectit won’t be delivered until you authenticate it.