# Set up DMARC reports

> Turn on DMARC reports for a sending domain, publish or update your _dmarc record with Emailit's reporting address, and upload reports you already have.

This guide shows how to start collecting DMARC reports for a sending domain. You turn reports on, add Emailit's reporting address to your DMARC record and wait for the first reports. You can also upload reports by hand.

## Before you begin

- Your workspace is on Pro, Business or Custom.
- The domain is added in **Email API → Domains**.
- You can edit the domain's DNS records.

## Turn on reports

**Dashboard**

  Go to **Email API → DMARC reports** and turn on the **Reports** switch next to the domain.

  You can also open the domain in **Email API → Domains** and turn on **Enable reports** in the **DMARC reports** card.

  The card then shows two values with copy buttons:

  - **Reporting address**, such as `k7f2m9qx4tz1@dmarc.emailitmail.com`
  - **Suggested _dmarc TXT**, a complete DMARC record that uses that address

**API**

  Call [Update a domain](/docs/api-reference/domains/update/) with `dmarc_reports`:

```bash
curl https://api.emailit.com/v2/domains/acme.com \
  -X POST \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "dmarc_reports": true }'
```

  The response includes the reporting address in `dmarc_address`, and the DMARC item in `dns_records` contains the suggested record. On Pay as you go, the request returns `403` with `"error": "plan_required"`.

The reporting address belongs to this domain and doesn't change. If you turn reports off and on again, you get the same address. While reports are off, Emailit discards reports sent to it.

## Publish the DMARC record

DMARC lives in one TXT record at `_dmarc.<domain>`. What you do depends on whether that record already exists. Check with:

```bash
dig +short TXT _dmarc.acme.com @1.1.1.1
```

### If you don't have a DMARC record

Create a TXT record at `_dmarc` with the **Suggested _dmarc TXT** value:

```txt
_dmarc.acme.com.   TXT   "v=DMARC1; p=none; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com;"
```

`p=none` only asks for reports. It doesn't change how your mail is delivered.

### If you already have a DMARC record

Don't create a second record. Receivers ignore DMARC when a domain has two. Instead, add Emailit's address to the existing `rua` and `ruf` tags, separated by commas, and keep your current policy.

| Before | After |
| --- | --- |
| `v=DMARC1; p=none;` | `v=DMARC1; p=none; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com;` |
| `v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com;` | `v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com,mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com;` |
| `v=DMARC1; p=reject; rua=mailto:a@vendor.example; ruf=mailto:f@vendor.example; fo=1` | `v=DMARC1; p=reject; rua=mailto:a@vendor.example,mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:f@vendor.example,mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; fo=1` |

Leave out the `ruf` part if you don't want forensic reports, which can contain personal data.

### If you send from a subdomain

If your sending domain is `mail.acme.com` but your DMARC record is on `acme.com`, you can add the address to the `_dmarc.acme.com` record. Emailit accepts reports for the sending domain, its subdomains and its parent domain. Reports about other domains are rejected.

> **Note:** [Cloudflare one-click setup](/docs/domains/cloudflare/) creates the suggested DMARC record only when the zone has none. It never edits an existing DMARC record, so merge the address yourself.

## Wait for the first reports

Mailbox providers send aggregate reports about once a day, covering the previous day. The first ones usually arrive within 24 to 48 hours of publishing the record, if you sent mail to those providers in that time.

Reports appear in **Email API → DMARC reports** on the domain's **Reports** tab, and the **Overview** fills in as they arrive.

## Upload a report manually

If you already have reports, for example from another DMARC tool or a mailbox where they used to arrive, upload them.

**Dashboard**

  1. **Open the domain's reports.** In **Email API → DMARC reports**, select the domain.

  2. **Select Upload report.** Choose an aggregate report (`.xml`, `.xml.gz` or `.zip`) or a forensic report (`.eml`). The file can be up to 10 MB.

  3. **Check the result.** Emailit processes the file and shows one of: **Report processed successfully.**, **This report was already imported.**, **Report queued for processing.** or **Report processing failed.**

**API**

  Call [Upload a report](/docs/api-reference/dmarc/upload/) with the file in base64:

```bash
curl https://api.emailit.com/v2/domains/acme.com/dmarc/reports \
  -X POST \
  -H "Authorization: Bearer $EMAILIT_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{
    \"filename\": \"google.com!acme.com!1759190400!1759276799.xml.gz\",
    \"content_base64\": \"$(base64 < report.xml.gz | tr -d '\n')\"
  }"
```

  Emailit responds with `202` and a report object with `"status": "pending"`. Processing runs in the background. Call [Retrieve a report](/docs/api-reference/dmarc/get/) to see whether it became `processed`, `duplicate` or `failed`. Files over 10 MB return `413`.

Uploads work even when the **Reports** switch is off. Emailit detects duplicates, so uploading the same report twice doesn't double your numbers. A report about a different domain fails with "Reported domain … does not match …".

## Troubleshooting

| Problem | Fix |
| --- | --- |
| No reports after 48 hours | Check that `dig +short TXT _dmarc.acme.com` returns exactly one record and that it contains your reporting address. Make sure the **Reports** switch is on. |
| Reports from only one or two providers | Providers only report on mail they received. Low-volume domains often get few reports. |
| No forensic reports | Normal. Many providers, including Gmail, don't send them. |
| `403 plan_required` when turning on reports | DMARC reports need Pro, Business or Custom. |

## Related

  - [Read DMARC reports](/docs/dmarc/reports/): Understand pass rates and move to enforcement.
  - [DNS records](/docs/domains/dns-records/#dmarc-txt-optional): How DMARC fits with your other records.

---
Source: https://emailit.com/docs/dmarc/set-up/
