Reports & AI threat analysis
Thousands of DMARC reports per month – who should read them? The DMARC Analyzer does it for you: it collects aggregate and forensic reports, uses AI to detect spoofing attempts and unauthorized senders, and delivers understandable reports with concrete recommendations.
What you get
AI threat analysis
Detects suspicious patterns: unauthorized senders, failures, phishing attempts.
Aggregate + forensic
RUA and RUF reports in one dashboard.
Whitelabel PDF reports
Customer reports with your logo – perfect for IT service providers.
Alerting
Immediate notification on spoofing attacks against your domain.
Policy progress
Guided path from p=none to p=reject with risk assessment.
Features in detail
AI threat analysis
Detects suspicious patterns: unauthorized senders, failures, phishing attempts.
Aggregate + forensic
RUA and RUF reports in one dashboard.
Whitelabel PDF reports
Customer reports with your logo – perfect for IT service providers.
Alerting
Immediate notification on spoofing attacks against your domain.
Policy progress
Guided path from p=none to p=reject with risk assessment.
Team & multi-domain
Multiple domains and team members with granular permissions.
How it works
1. Set report address
Point rua/ruf in your DMARC record to our address.
2. Collect reports
We automatically process all incoming reports.
3. Detect threats
The AI analyzes senders, failures and patterns – you get clear recommendations.
Frequently asked questions
What are DMARC reports?
Mail providers like Google and Microsoft send daily XML reports about all email sent on behalf of your domain: volume, SPF/DKIM alignment and source IPs. The DMARC Analyzer turns them into a readable dashboard.
How often do I receive DMARC reports?
Major providers send daily — usually around midnight UTC, covering the previous day. Smaller providers send weekly or not at all.
What does the DMARC dashboard show?
Daily volume, SPF/DKIM/DMARC pass rates, top source IPs with organization and country, identified legitimate services (newsletter, CRM) and suspicious sources — plus AI threat analysis on suspicious patterns.
How do I start with p=none?
Set the DMARC record with p=none and rua=mailto:address. After 2-4 weeks of reports you see all legitimate senders. Only when the pass rate is high, move to quarantine — and later reject.
How long does setup take?
About 10 minutes: add the rua address to your DMARC record, done. First reports arrive within 24 hours.
Is AI analysis included in every plan?
AI threat analysis is available from the Starter plan. Basic analysis (alignment, sources, countries) is always included.
Can I export reports as PDF?
Yes – with whitelabel option (your logo) from the Professional plan, ideal for IT service providers in customer reporting.
Related guides
Ready? Start in seconds.
Create a free account and start instantly.
Start now