Aggregate reports are XML, verbose, and arrive daily from every mailbox provider. Once you know the shape, though, each one answers a single question: who sent mail as my domain, and did it authenticate?
Want to see it in action? Paste a report into the free DMARC report analyzer — it parses in your browser, nothing uploaded.
The envelope
The top of the report says who generated it and which policy they saw published:
<report_metadata>
<org_name>google.com</org_name>
<date_range><begin>...</begin><end>...</end></date_range>
</report_metadata>
<policy_published>
<domain>yourdomain.com</domain>
<p>none</p>
</policy_published>
The rows are where the signal is
Each <record> groups messages by sending source:
<record>
<row>
<source_ip>203.0.113.10</source_ip>
<count>128</count>
<policy_evaluated>
<dkim>pass</dkim>
<spf>fail</spf>
</policy_evaluated>
</row>
</record>
Read it as: 128 messages from 203.0.113.10; DKIM passed and aligned, SPF did not. Because DMARC passes when either mechanism passes and aligns, this row is a DMARC pass — no action needed.
Which rows actually need action
- Both
pass— legitimate, aligned mail. Ignore. - One
pass, onefail— usually fine (DMARC still passes), but worth fixing the failing mechanism before you tighten policy. - Both
fail, but you recognise the source — a legitimate sender you forgot to authenticate. Add it to SPF or set up DKIM for it. - Both
fail, unfamiliar source — either shadow IT or someone spoofing your domain. This is exactly what DMARC exists to surface. - Both
fail, and the source is a forwarder or a mailing list — legitimate mail taking a route that breaks authentication. These rows never go away, so they must not gate enforcement; ARC explains why, and why it is not the fix people hope it is.
Doing this at scale
One domain is readable by hand. A portfolio of client domains, each with dozens of sources and a report from every provider every day, is not — that is what a self-hosted analyzer like DMARC Analyzer aggregates for you, every domain in one dashboard. The DNS and process side of running that portfolio is its own job: see DMARC for many client domains. When the “both fail, legitimate” rows are gone, you are ready to move toward enforcement.