DMARC Report Analyzer

Upload DMARC aggregate reports (.xml, .gz, .zip — multiple files or a whole folder) to see who is sending as your domain, what failed or was blocked, and how to fix it.

Private by design: reports are parsed and analyzed entirely in your browser and saved only to this browser's local storage. Only your domain name, DKIM selector names, and sender IPs are sent to this server — for live DNS checks — never report contents.

Drop report files or folders here, or choose files / choose a folder
Accepts .xml, .xml.gz, .zip — e.g. google.com!yourdomain.com!…!….zip
Parsing…
No reports yet. Drop some report files above to get started.
Not receiving reports? Add rua=mailto:you@yourdomain.com to your DMARC record.
Findings & suggestions
Suggested fixes likely omissions & mistakes, with the records to publish
Daily volume
Source classification
Sending sources
Source IPIdentified asMsgs ClassAuthBlocked
Current DNS state full DNS + mail check →
Checking DNS…
DKIM selectors signing as you
Reporter differences
Delivered-to domains (where reporters include them)
Saved reports (stored in this browser only)
DomainReportsCoverage
Nothing saved yet.

DMARC aggregate reports are XML files that mail receivers (Google, Microsoft, Yahoo…) email you daily when your domain publishes a DMARC record with an rua= address. Each report lists the IPs that sent mail claiming to be your domain, how many messages, and whether they passed SPF and DKIM alignment. They contain counts per sending IP — not individual emails, subjects, or bodies.

Classification: Passing all mail authenticated · Mixed some passed, some failed (often forwarding) · Investigate failing, but carries signals it may be your own mail · Likely spoofing failing with no connection to your infrastructure.

Dispositions: what receivers actually did — none (delivered), quarantine (spam folder), reject (refused). With p=none nothing is blocked; the analyzer simulates what a stricter policy would have done.

History is kept in your browser's IndexedDB. Re-uploading the same report is deduplicated automatically. Use Backup/Restore to move it between browsers.