DMARC report XML analyzer
Drop a DMARC report here to analyze it in your browser.
Understand your DMARC aggregate report
DMARC report analysis
Turn raw DMARC XML into a clear summary of sending sources, authentication results, and failures. For continuous reporting across every provider, use Suped's DMARC monitoring.
Get started
DMARC report analysis
Review source IPs, message volume, SPF and DKIM alignment, DMARC results, and policy actions.
DMARC aligned
SPF passed
DKIM signed
Authentication results
See DMARC, SPF, and DKIM pass rates without reading raw XML elements.
DNS provider
Managed in Cloudflare
Sending source breakdown
Group source IPs into recognizable sending services and compare message volume.
DMARC
p=quarantineSPF failures protected
Alignment visibility
Understand whether SPF and DKIM aligned with the visible From domain.
p=nonequarantinereject
Policy actions
Review whether receivers applied none, quarantine, or reject to failed messages.
Priority fix
Move DMARC from monitoring to quarantine after sender alignment passes.
Failure triage
Separate legitimate sender configuration problems from blocked spoofing attempts.
Record found
Single record
Record valid
Readable report details
Inspect report provider, date range, domain, report ID, and message counts in one view.
DMARC XML analyzer FAQs
Answers to common questions about aggregate DMARC XML reports and their authentication results.
It is a machine readable report sent by participating mailbox providers. It summarizes messages using your domain, their source IPs, SPF and DKIM authentication, DMARC alignment, and the policy action applied.
No. It only reads the uploaded report and presents its contents. It does not change DNS, sender configuration, or your published DMARC policy.
DMARC passes when either SPF or DKIM passes and aligns with the visible From domain. A message can therefore fail SPF but pass DMARC through an aligned DKIM signature.
It means the source IP was not identified as a recognized sending service. It may be an unauthorized sender, a legitimate service that needs configuration, or a source that cannot be identified from the report alone.
No. Failures from legitimate senders usually need SPF or DKIM alignment work. Failures from unauthorized sources can show that quarantine or reject is correctly protecting the domain.
No. Each report covers mail observed by one reporting provider during a specific period. A complete view requires reports from multiple mailbox providers over time.

How MONEYME proactively strengthens domain security and unlocks higher email engagement with Suped
See how MONEYME uses Suped
How cybersecurity specialist Jam Cyber delivers scalable DMARC protection with Suped
See how Jam Cyber uses Suped

How Vision Australia maintains full DMARC enforcement across a large domain portfolio with Suped
See how Vision Australia uses Suped

How The POP Team turns domain checks and DMARC visibility into client ready delivery work
See how The POP Team uses Suped

How DigiBean simplified DMARC monitoring and improved email security for their MSP clients
See how DigiBean uses Suped

How Alliance Group moved from reactive guesswork to proactive email management with Suped
See how Alliance Group uses Suped
Start monitoring your DMARC reports today

What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing

