The Four Overview Cards
At the top of every DMARC report, you see four colored cards that give you an instant snapshot of your email authentication health:
1. Total Emails (Blue)
The total number of emails that receivers processed for your domain during the report period. This includes all emails — both legitimate and potentially forged ones.
- High numbers from unknown IPs: Could indicate someone is spoofing your domain.
- Unexpected spikes: May indicate a phishing campaign using your domain.
- Lower than expected: Your DMARC record may not be receiving all reports. Check your
ruatag.
2. DKIM Pass Rate (Green)
The percentage of emails where the DKIM signature was valid and aligned with the "From" domain. A DKIM pass means:
- The email was cryptographically signed by an authorized server
- The signature matched the message content (not tampered)
- The signing domain aligns with the "From" domain
Target: 95–100%. If below 90%, check if all your sending services (newsletter, CRM, support desk) have DKIM properly configured.
3. SPF Pass Rate (Purple)
The percentage of emails where the sending server's IP was authorized by your SPF record and the domain was aligned. SPF pass means:
- The sending IP is listed in your domain's SPF DNS record
- The envelope "Mail From" domain aligns with the "From" header
Target: 95–100%. Lower rates often mean you have sending services not listed in your SPF record, or third-party services sending with a different envelope domain.
4. Policy (Orange)
Your current DMARC policy that tells receivers what to do with unauthenticated emails:
- none: Monitor only — no action taken. Good for starting out.
- quarantine: Suspicious emails go to spam/junk folder.
- reject: Unauthenticated emails are blocked entirely. Maximum protection.
Goal: Work towards p=reject. Start with none, analyze reports, fix issues, then move to quarantine, and finally reject.
DMARC Policy Details — The Five Fields
The "Policy Details" card shows the DMARC policy that was published for your domain when the report was generated. Here's what each field means:
Domain
The domain this report covers. This is the domain from your DMARC DNS record (_dmarc.yourdomain.com).
Policy (p)
The main DMARC policy. This is the most important setting:
none | Take no action. Just collect reports. Use this when you're first setting up DMARC to understand your email flows without risking delivery. |
quarantine | Mark failing emails as suspicious. They typically land in spam. Good intermediate step. |
reject | Block failing emails entirely. The receiver should not deliver them at all. Maximum protection, but make sure all legitimate sources pass first! |
Subdomain Policy (sp)
Policy specifically for subdomains (e.g., mail.yourdomain.com, newsletter.yourdomain.com). If not set, the main policy (p) applies to subdomains too.
Best practice: Set sp=reject for unused subdomains to prevent subdomain spoofing.
DKIM Alignment (adkim)
How strictly the DKIM signing domain must match the "From" domain:
- Relaxed (r): The DKIM signing domain can be a subdomain of the "From" domain. E.g., a signature from
mail.example.compasses forexample.com. This is the default and recommended for most setups. - Strict (s): The DKIM signing domain must exactly match the "From" domain. More secure but can break legitimate mail from subdomains.
SPF Alignment (aspf)
How strictly the SPF domain (envelope "Mail From") must match the "From" domain:
- Relaxed (r): The SPF domain can be a subdomain of the "From" domain. Default and recommended.
- Strict (s): Exact match required. Can cause issues with forwarded mail and some third-party services.
Source IP Records — Reading the Table
The Source IP Records table is the heart of every DMARC report. Each row represents a group of emails from the same source IP with the same authentication results. Here's what each column means:
Source IP
The IP address of the server that sent the emails. This tells you who is sending mail as your domain. Common scenarios:
- Your own mail server IP: Legitimate mail from your infrastructure.
- Known service IPs (Google, Microsoft 365, Mailchimp, etc.): Third-party services sending on your behalf.
- Unknown IPs: Either a service you forgot about, or someone trying to spoof your domain. Look up the IP to investigate.
Header From
The domain in the email's "From" header — what the recipient sees as the sender. This should be your domain or a subdomain.
Count
The number of emails sent from this IP with this exact authentication result. A high count from an unknown IP with failing DKIM/SPF is a strong indicator of spoofing or phishing.
Disposition
What the receiver actually did with these emails, based on your DMARC policy:
| none | No action taken. The email was delivered normally. This happens when your policy is p=none, or when both DKIM and SPF pass. |
| quarantine | The email was placed in the recipient's spam/junk folder. |
| reject | The email was rejected/blocked entirely and not delivered. |
DKIM (Pass/Fail)
Whether the email's DKIM signature was valid and aligned with your domain:
- Pass ✓: The email had a valid DKIM signature from your domain (or an aligned subdomain).
- Fail ✗: The DKIM signature was missing, invalid, or from a domain that doesn't align with yours. Common causes: misconfigured DKIM keys on sending service, email modified in transit, or spoofing attempt.
SPF (Pass/Fail)
Whether the sending IP was authorized by your SPF record:
- Pass ✓: The IP is listed in your SPF DNS record and the domain is aligned.
- Fail ✗: The IP is NOT in your SPF record, or the envelope domain doesn't align. Common causes: new service not added to SPF, forwarded email (breaks SPF), or spoofing.
Auth Details
Detailed authentication results including the specific domains and selectors used for DKIM and SPF checks. Useful for debugging specific failures.
Green rows (DKIM Pass + SPF Pass) = Properly authenticated mail. ✓
Red/highlighted rows (any Fail) = Needs investigation. Either fix the source's authentication, or if it's a spoofing attempt, your
reject policy will block it.
Compliance Rate, Trends & What to Aim For
Your DMARC compliance rate is the percentage of emails that pass both DKIM or SPF (with alignment). This is the single most important metric in the DMARC Analyzer.
Compliance Rate Targets
| 98–100% | 🟢 Excellent. Safe to enforce p=reject. |
| 90–98% | 🟡 Good. Investigate the failing sources. Usually 1-2 services need DKIM/SPF fixes. |
| 70–90% | 🟠 Needs work. Multiple sending services likely misconfigured. Don't enforce reject yet. |
| Below 70% | 🔴 Critical. Major gaps in authentication. Stay on p=none and fix all sources first. |
Reading the Trend Chart
The trend chart shows your compliance rate over time (7 days, 30 days, 90 days, or 12 months):
- Upward trend: Your authentication improvements are working.
- Sudden drops: A new service started sending without proper DKIM/SPF, or a DNS change broke your records.
- Flat line at 100%: Perfect — all legitimate mail is authenticated.
- Spikes in total volume + low compliance: Someone may be running a spoofing campaign against your domain.
The Path to p=reject
- Week 1–2: Set
p=none. Collect reports. Identify all legitimate sending sources. - Week 3–4: Configure DKIM and SPF for every sending source. Watch compliance rate climb.
- Month 2: Once compliance is >95%, switch to
p=quarantine. Monitor for any legitimate mail going to spam. - Month 3+: Once compliance is >98% and stable, switch to
p=reject. Maximum protection achieved.
pct tag when transitioning policies. For example, p=quarantine; pct=10 applies quarantine to only 10% of failing emails, letting you test gradually.
Forensic (Failure) Reports — RUF
Forensic reports (also called "failure reports" or RUF reports) are detailed reports about individual emails that failed DMARC authentication. Unlike aggregate reports (RUA) which summarize, forensic reports give you the actual email details.
What Forensic Reports Contain
- Original email headers: Including the complete authentication chain
- From address: The spoofed or misaligned sender
- Subject line: Helps identify if it's phishing or a misconfigured service
- Authentication results: Exactly which checks failed and why
- Sending IP: The server that sent the failing email
Why Forensic Reports Are Valuable
While aggregate reports tell you "100 emails from IP 1.2.3.4 failed DKIM", forensic reports tell you "here is the exact email with subject 'Invoice #12345' that failed because the DKIM selector was wrong". This makes debugging much faster.
Privacy Note
Not all providers send forensic reports due to privacy concerns (they contain email content). Major providers like Google do not send RUF reports. Microsoft and some smaller providers do.
Setting Up Forensic Reports
Add the ruf tag to your DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@example.com; ruf=mailto:forensic@example.com; fo=1
The fo tag controls when forensic reports are generated:
fo=0— Only when both DKIM and SPF fail (default)fo=1— When either DKIM or SPF fails (recommended — more data)fo=d— When DKIM failsfo=s— When SPF fails
Common Patterns & What They Mean
Here are the most common patterns you'll see in the DMARC Analyzer and how to interpret them:
🟢 Pattern 1: High Volume, All Pass
Many emails from your mail server IP, all DKIM Pass + SPF Pass, disposition "none".
Meaning: Your legitimate mail is properly authenticated. Everything is working as expected.
🟡 Pattern 2: Third-Party Service Failing DKIM
Emails from a known service (e.g., Mailchimp, Freshdesk) with DKIM Fail but SPF Pass.
Action: Set up DKIM signing in the service's settings. Most services provide a CNAME record to add to your DNS.
🟡 Pattern 3: Forwarded Mail Failing SPF
Emails from university or corporate forwarders with SPF Fail but DKIM Pass.
Meaning: Email forwarding breaks SPF because the forwarding server's IP is not in your SPF record. This is normal and expected. DKIM still passes because signatures survive forwarding. Your DMARC compliance is maintained through DKIM.
🔴 Pattern 4: Unknown IPs, All Fail
Emails from unknown IPs with DKIM Fail + SPF Fail, often with high volume.
Meaning: Someone is spoofing your domain! With p=reject, these emails will be blocked. This is exactly what DMARC is designed to protect against.
🔴 Pattern 5: Your Own IP Failing
Emails from your known mail server IP with DKIM or SPF failures.
Action: Urgent fix needed. Check your DKIM keys (expired?), SPF record (IP missing?), and DNS settings. This affects your legitimate mail delivery.
🟠 Pattern 6: Disposition "quarantine" for Legitimate Mail
Known good sources being quarantined because they fail authentication.
Action: Fix the authentication for these sources before moving to p=reject. Consider temporarily using pct=50 to reduce the impact while you fix things.
Related articles
Understanding DMARC Reports
How to read and interpret DMARC aggregate reports: XML structure, source IP analysis, and identifying threats.
ReadDMARC Deep Dive
Complete DMARC guide: policies, alignment modes, subdomain handling, and the path from monitoring to enforcement.
ReadTroubleshooting Guide
Common DMARC, SPF, and DKIM problems and how to diagnose and fix them.
Read