DMARC Report Analyzer
Upload DMARC aggregate reports (.xml, .gz, .zip — multiple files or a whole folder)
to see who is sending as your domain, what failed or was blocked, and how to fix it.
Private by design: reports are parsed and analyzed entirely in your browser and saved only to this browser's local storage. Only your domain name, DKIM selector names, and sender IPs are sent to this server — for live DNS checks — never report contents.
google.com!yourdomain.com!…!….zipNot receiving reports? Add
rua=mailto:you@yourdomain.com to your DMARC record.
| Source IP | Identified as | Msgs | Class | Auth | Blocked |
|---|
| Domain | Reports | Coverage | |
|---|---|---|---|
| Nothing saved yet. | |||
DMARC aggregate reports are XML files that mail receivers (Google, Microsoft, Yahoo…)
email you daily when your domain publishes a DMARC record with an rua= address. Each report
lists the IPs that sent mail claiming to be your domain, how many messages, and whether they passed
SPF and DKIM alignment. They contain counts per sending IP — not individual emails, subjects, or bodies.
Classification: Passing all mail authenticated · Mixed some passed, some failed (often forwarding) · Investigate failing, but carries signals it may be your own mail · Likely spoofing failing with no connection to your infrastructure.
Dispositions: what receivers actually did — none (delivered),
quarantine (spam folder), reject (refused). With p=none nothing is
blocked; the analyzer simulates what a stricter policy would have done.
History is kept in your browser's IndexedDB. Re-uploading the same report is deduplicated automatically. Use Backup/Restore to move it between browsers.