E-Mail-Authentifizierung & DMARC25 min read6 sections

Understanding the DMARC Analyzer Dashboard

A complete guide to every value, metric, and column shown in the DMARC Analyzer, with practical examples for interpreting your data.

01

The Four Overview Cards

At the top of every DMARC report, you see four colored cards that give you an instant snapshot of your email authentication health:

1. Total Emails (Blue)

The total number of emails that receivers processed for your domain during the report period. This includes all emails — both legitimate and potentially forged ones.

  • High numbers from unknown IPs: Could indicate someone is spoofing your domain.
  • Unexpected spikes: May indicate a phishing campaign using your domain.
  • Lower than expected: Your DMARC record may not be receiving all reports. Check your rua tag.

2. DKIM Pass Rate (Green)

The percentage of emails where the DKIM signature was valid and aligned with the "From" domain. A DKIM pass means:

  • The email was cryptographically signed by an authorized server
  • The signature matched the message content (not tampered)
  • The signing domain aligns with the "From" domain

Target: 95–100%. If below 90%, check if all your sending services (newsletter, CRM, support desk) have DKIM properly configured.

3. SPF Pass Rate (Purple)

The percentage of emails where the sending server's IP was authorized by your SPF record and the domain was aligned. SPF pass means:

  • The sending IP is listed in your domain's SPF DNS record
  • The envelope "Mail From" domain aligns with the "From" header

Target: 95–100%. Lower rates often mean you have sending services not listed in your SPF record, or third-party services sending with a different envelope domain.

4. Policy (Orange)

Your current DMARC policy that tells receivers what to do with unauthenticated emails:

  • none: Monitor only — no action taken. Good for starting out.
  • quarantine: Suspicious emails go to spam/junk folder.
  • reject: Unauthenticated emails are blocked entirely. Maximum protection.

Goal: Work towards p=reject. Start with none, analyze reports, fix issues, then move to quarantine, and finally reject.

02

DMARC Policy Details — The Five Fields

The "Policy Details" card shows the DMARC policy that was published for your domain when the report was generated. Here's what each field means:

Domain

The domain this report covers. This is the domain from your DMARC DNS record (_dmarc.yourdomain.com).

Policy (p)

The main DMARC policy. This is the most important setting:

noneTake no action. Just collect reports. Use this when you're first setting up DMARC to understand your email flows without risking delivery.
quarantineMark failing emails as suspicious. They typically land in spam. Good intermediate step.
rejectBlock failing emails entirely. The receiver should not deliver them at all. Maximum protection, but make sure all legitimate sources pass first!

Subdomain Policy (sp)

Policy specifically for subdomains (e.g., mail.yourdomain.com, newsletter.yourdomain.com). If not set, the main policy (p) applies to subdomains too.

Best practice: Set sp=reject for unused subdomains to prevent subdomain spoofing.

DKIM Alignment (adkim)

How strictly the DKIM signing domain must match the "From" domain:

  • Relaxed (r): The DKIM signing domain can be a subdomain of the "From" domain. E.g., a signature from mail.example.com passes for example.com. This is the default and recommended for most setups.
  • Strict (s): The DKIM signing domain must exactly match the "From" domain. More secure but can break legitimate mail from subdomains.

SPF Alignment (aspf)

How strictly the SPF domain (envelope "Mail From") must match the "From" domain:

  • Relaxed (r): The SPF domain can be a subdomain of the "From" domain. Default and recommended.
  • Strict (s): Exact match required. Can cause issues with forwarded mail and some third-party services.
⚠️ Practical Tip: Start with "Relaxed" alignment for both DKIM and SPF. Only switch to "Strict" if you have full control over all sending infrastructure and don't use complex mail routing.
03

Source IP Records — Reading the Table

The Source IP Records table is the heart of every DMARC report. Each row represents a group of emails from the same source IP with the same authentication results. Here's what each column means:

Source IP

The IP address of the server that sent the emails. This tells you who is sending mail as your domain. Common scenarios:

  • Your own mail server IP: Legitimate mail from your infrastructure.
  • Known service IPs (Google, Microsoft 365, Mailchimp, etc.): Third-party services sending on your behalf.
  • Unknown IPs: Either a service you forgot about, or someone trying to spoof your domain. Look up the IP to investigate.

Header From

The domain in the email's "From" header — what the recipient sees as the sender. This should be your domain or a subdomain.

Count

The number of emails sent from this IP with this exact authentication result. A high count from an unknown IP with failing DKIM/SPF is a strong indicator of spoofing or phishing.

Disposition

What the receiver actually did with these emails, based on your DMARC policy:

noneNo action taken. The email was delivered normally. This happens when your policy is p=none, or when both DKIM and SPF pass.
quarantineThe email was placed in the recipient's spam/junk folder.
rejectThe email was rejected/blocked entirely and not delivered.

DKIM (Pass/Fail)

Whether the email's DKIM signature was valid and aligned with your domain:

  • Pass ✓: The email had a valid DKIM signature from your domain (or an aligned subdomain).
  • Fail ✗: The DKIM signature was missing, invalid, or from a domain that doesn't align with yours. Common causes: misconfigured DKIM keys on sending service, email modified in transit, or spoofing attempt.

SPF (Pass/Fail)

Whether the sending IP was authorized by your SPF record:

  • Pass ✓: The IP is listed in your SPF DNS record and the domain is aligned.
  • Fail ✗: The IP is NOT in your SPF record, or the envelope domain doesn't align. Common causes: new service not added to SPF, forwarded email (breaks SPF), or spoofing.

Auth Details

Detailed authentication results including the specific domains and selectors used for DKIM and SPF checks. Useful for debugging specific failures.

🎯 How to Read the Table:
Green rows (DKIM Pass + SPF Pass) = Properly authenticated mail. ✓
Red/highlighted rows (any Fail) = Needs investigation. Either fix the source's authentication, or if it's a spoofing attempt, your reject policy will block it.
05

Forensic (Failure) Reports — RUF

Forensic reports (also called "failure reports" or RUF reports) are detailed reports about individual emails that failed DMARC authentication. Unlike aggregate reports (RUA) which summarize, forensic reports give you the actual email details.

What Forensic Reports Contain

  • Original email headers: Including the complete authentication chain
  • From address: The spoofed or misaligned sender
  • Subject line: Helps identify if it's phishing or a misconfigured service
  • Authentication results: Exactly which checks failed and why
  • Sending IP: The server that sent the failing email

Why Forensic Reports Are Valuable

While aggregate reports tell you "100 emails from IP 1.2.3.4 failed DKIM", forensic reports tell you "here is the exact email with subject 'Invoice #12345' that failed because the DKIM selector was wrong". This makes debugging much faster.

Privacy Note

Not all providers send forensic reports due to privacy concerns (they contain email content). Major providers like Google do not send RUF reports. Microsoft and some smaller providers do.

Setting Up Forensic Reports

Add the ruf tag to your DMARC record:

v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; ruf=mailto:forensic@example.com; fo=1

The fo tag controls when forensic reports are generated:

  • fo=0 — Only when both DKIM and SPF fail (default)
  • fo=1 — When either DKIM or SPF fails (recommended — more data)
  • fo=d — When DKIM fails
  • fo=s — When SPF fails
06

Common Patterns & What They Mean

Here are the most common patterns you'll see in the DMARC Analyzer and how to interpret them:

🟢 Pattern 1: High Volume, All Pass

Many emails from your mail server IP, all DKIM Pass + SPF Pass, disposition "none".

Meaning: Your legitimate mail is properly authenticated. Everything is working as expected.

🟡 Pattern 2: Third-Party Service Failing DKIM

Emails from a known service (e.g., Mailchimp, Freshdesk) with DKIM Fail but SPF Pass.

Action: Set up DKIM signing in the service's settings. Most services provide a CNAME record to add to your DNS.

🟡 Pattern 3: Forwarded Mail Failing SPF

Emails from university or corporate forwarders with SPF Fail but DKIM Pass.

Meaning: Email forwarding breaks SPF because the forwarding server's IP is not in your SPF record. This is normal and expected. DKIM still passes because signatures survive forwarding. Your DMARC compliance is maintained through DKIM.

🔴 Pattern 4: Unknown IPs, All Fail

Emails from unknown IPs with DKIM Fail + SPF Fail, often with high volume.

Meaning: Someone is spoofing your domain! With p=reject, these emails will be blocked. This is exactly what DMARC is designed to protect against.

🔴 Pattern 5: Your Own IP Failing

Emails from your known mail server IP with DKIM or SPF failures.

Action: Urgent fix needed. Check your DKIM keys (expired?), SPF record (IP missing?), and DNS settings. This affects your legitimate mail delivery.

🟠 Pattern 6: Disposition "quarantine" for Legitimate Mail

Known good sources being quarantined because they fail authentication.

Action: Fix the authentication for these sources before moving to p=reject. Consider temporarily using pct=50 to reduce the impact while you fix things.