How-to
Set up DMARC reports
Turn on DMARC reports for a sending domain, publish or update your _dmarc record with Emailit's reporting address, and upload reports you already have.
This guide shows how to start collecting DMARC reports for a sending domain. You turn reports on, add Emailit’s reporting address to your DMARC record and wait for the first reports. You can also upload reports by hand.
Before you begin
- Your workspace is on Pro, Business or Custom.
- The domain is added in Email APIDomains.
- You can edit the domain’s DNS records.
Turn on reports
Go to Email APIDMARC reports and turn on the Reports switch next to the domain.
You can also open the domain in Email APIDomains and turn on Enable reports in the DMARC reports card.
The card then shows two values with copy buttons:
- Reporting address, such as
k7f2m9qx4tz1@dmarc.emailitmail.com - Suggested _dmarc TXT, a complete DMARC record that uses that address
Call Update a domain with dmarc_reports:
curl https://api.emailit.com/v2/domains/acme.com \
-X POST \
-H "Authorization: Bearer $EMAILIT_API_KEY" \
-H "Content-Type: application/json" \
-d '{ "dmarc_reports": true }'The response includes the reporting address in dmarc_address, and the DMARC item in dns_records contains the suggested record. On Pay as you go, the request returns 403 with "error": "plan_required".
The reporting address belongs to this domain and doesn’t change. If you turn reports off and on again, you get the same address. While reports are off, Emailit discards reports sent to it.
Publish the DMARC record
DMARC lives in one TXT record at _dmarc.<domain>. What you do depends on whether that record already exists. Check with:
dig +short TXT _dmarc.acme.com @1.1.1.1If you don’t have a DMARC record
Create a TXT record at _dmarc with the Suggested _dmarc TXT value:
_dmarc.acme.com. TXT "v=DMARC1; p=none; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com;"p=none only asks for reports. It doesn’t change how your mail is delivered.
If you already have a DMARC record
Don’t create a second record. Receivers ignore DMARC when a domain has two. Instead, add Emailit’s address to the existing rua and ruf tags, separated by commas, and keep your current policy.
| Before | After |
|---|---|
v=DMARC1; p=none; |
v=DMARC1; p=none; rua=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; |
v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com; |
v=DMARC1; p=quarantine; rua=mailto:dmarc@acme.com,mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; |
v=DMARC1; p=reject; rua=mailto:a@vendor.example; ruf=mailto:f@vendor.example; fo=1 |
v=DMARC1; p=reject; rua=mailto:a@vendor.example,mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; ruf=mailto:f@vendor.example,mailto:k7f2m9qx4tz1@dmarc.emailitmail.com; fo=1 |
Leave out the ruf part if you don’t want forensic reports, which can contain personal data.
If you send from a subdomain
If your sending domain is mail.acme.com but your DMARC record is on acme.com, you can add the address to the _dmarc.acme.com record. Emailit accepts reports for the sending domain, its subdomains and its parent domain. Reports about other domains are rejected.
Wait for the first reports
Mailbox providers send aggregate reports about once a day, covering the previous day. The first ones usually arrive within 24 to 48 hours of publishing the record, if you sent mail to those providers in that time.
Reports appear in Email APIDMARC reports on the domain’s Reports tab, and the Overview fills in as they arrive.
Upload a report manually
If you already have reports, for example from another DMARC tool or a mailbox where they used to arrive, upload them.
-
Open the domain’s reports. In Email APIDMARC reports, select the domain.
-
Select Upload report. Choose an aggregate report (
.xml,.xml.gzor.zip) or a forensic report (.eml). The file can be up to 10 MB. -
Check the result. Emailit processes the file and shows one of: Report processed successfully., This report was already imported., Report queued for processing. or Report processing failed.
Call Upload a report with the file in base64:
curl https://api.emailit.com/v2/domains/acme.com/dmarc/reports \
-X POST \
-H "Authorization: Bearer $EMAILIT_API_KEY" \
-H "Content-Type: application/json" \
-d "{
\"filename\": \"google.com!acme.com!1759190400!1759276799.xml.gz\",
\"content_base64\": \"$(base64 < report.xml.gz | tr -d '\n')\"
}"Emailit responds with 202 and a report object with "status": "pending". Processing runs in the background. Call Retrieve a report to see whether it became processed, duplicate or failed. Files over 10 MB return 413.
Uploads work even when the Reports switch is off. Emailit detects duplicates, so uploading the same report twice doesn’t double your numbers. A report about a different domain fails with “Reported domain … does not match …”.
Troubleshooting
| Problem | Fix |
|---|---|
| No reports after 48 hours | Check that dig +short TXT _dmarc.acme.com returns exactly one record and that it contains your reporting address. Make sure the Reports switch is on. |
| Reports from only one or two providers | Providers only report on mail they received. Low-volume domains often get few reports. |
| No forensic reports | Normal. Many providers, including Gmail, don’t send them. |
403 plan_required when turning on reports |
DMARC reports need Pro, Business or Custom. |