DMARC Reporting, Made Readable

See exactly who’s sending email as your domain – without digging through raw XML.

DMARC generates a constant stream of aggregate and failure reports, but on their own, they’re a wall of machine-readable data that nobody wants to open. PowerDMARC turns that raw feed into clear, visual dashboards, so you can see your entire email authentication picture at a glance instead of parsing files line by line.

Start 15-day trial Book a demo
Authentication Overview Live
94% Pass
12,480 emails evaluated this week
SPF Pass
DKIM Pass
DMARC Enforced
1,204 sources monitored
Weekly volume

What is DMARC Reporting?

DMARC reporting is the feedback mechanism built into the DMARC standard that allows mailbox providers to tell you which servers are sending mail as your domain, and whether that mail passed or failed SPF and DKIM authentication. It comes in two forms, and it’s worth knowing the difference before you dig in.

Aggregate Reports (RUA)

DMARC aggregate reports are sent daily in XML format by mailbox providers like Google, Microsoft, and Yahoo. They summarize, in bulk, every message claiming to come from your domain, how it was authenticated, whether it passed SPF and DKIM, and where it originated.

Failure Reports (RUF)

DMARC failure reports are sent per-incident in ARF, in near real time, when a specific message fails authentication. They contain more granular detail about individual failures, though far fewer providers support them today.

Why Is a DMARC Reporting Service Needed?

Raw reports contain the answers to who’s sending mail as your domain and how well it’s authenticating, but you need a way to actually see them. A dedicated reporting service lets you:

See who's sending as your domain

Every legitimate service and every impersonator, in one place.

Find authentication gaps before you enforce

Spot misconfigured SPF or DKIM records before you move to a stricter DMARC policy and risk blocking real mail.

Detect abuse and spoofing

Catch domains and IPs sending unauthorized mail on your behalf, often the first sign of a phishing campaign.

Prove and maintain compliance

Keep an audit trail for security reviews, cyber insurance, and regulatory requirements without manually archiving XML files.

The Reporting Views You Get

This is where PowerDMARC does the heavy lifting. Instead of one flat report, you get seven distinct views into your email traffic, each one answering a different question about who’s sending mail as you, and how well-authenticated it is.

Per Sending Source report screenshot

Per Sending Source

Vendor audit Shadow IT detection Sender verification

See every service and IP address sending mail on your behalf, like your email marketing platform, CRM, helpdesk, and anything else, along with how each one authenticates. Use it to confirm every legitimate sender is properly configured, and to spot ones that aren't yours at all.

Per Result report screenshot

Per Result

Quick Pass/Fail scan Alignment gaps Pre-enforcement readiness

A straightforward pass/fail breakdown across DMARC, SPF, and DKIM. This is the fastest way to spot alignment failures, which are often the first sign something needs fixing before enforcement.

Per Organization report screenshot

Per Organization

Provider coverage Google & Microsoft view Reporting consistency

Reports grouped by the mailbox provider that sent them (Google, Microsoft, Yahoo, and others). Use this view to confirm you're getting consistent coverage across every major provider your recipients use, not just the one or two that report most often.

Per Host report screenshot

Per Host

Server-level detail Infrastructure tracing Root-cause pinpointing

Drill down from IP-level data into the individual sending hosts and servers behind it. Useful when you need to trace a problem back to a specific piece of infrastructure rather than a whole service.

Detailed Stats report screenshot

Detailed Stats

Trend tracking Compliance over time Policy progress proof

Aggregate pass rates, volume trends, and compliance percentages over time. This is your long-view dashboard to track whether authentication is improving as you tighten your policy, and catch any regressions early.

Geolocation Report screenshot

Geolocation Report

Origin mapping Suspicious-region flagging Visual risk scan

See where mail claiming your domain actually originates on a map. If you don't send from certain regions, unexpected volume from there is an immediate red flag worth investigating.

Per Country report screenshot

Per Country

Country-level volume Abuse pattern detection Regional risk priority

Country-level volume and abuse detection, built to pair with the geolocation view. Use it to spot spoofing patterns concentrated in specific countries and prioritize where to dig in first.

PowerDMARC Reporting Features

Human-readable dashboards

Every view above, rendered visually instead of as raw tables.

Scheduled exports

Get reports delivered on a cadence that fits your review process.

Real-time Alerting

Get notified when authentication failures or suspicious sending patterns spike.

RUF with PGP encryption

Get per-incident failure detail in real time, with the option to encrypt reports so only authorized users can read the contents of failed messages.

11-language support

The platform and reports are available in English, Spanish, French, German, Japanese, Italian, Dutch, Swedish, Norwegian, Russian, and Portuguese.

Multi-domain management

Manage reporting across every domain you own from a single view.

MSP / white-label support

Built for partners who want to manage DMARC reporting across multiple client domains, under their own brand.

Explore the full platform

Frequently Asked Questions

What is a DMARC report?
A DMARC report is data sent by mailbox providers that shows how mail claiming to be from your domain performed against SPF and DKIM authentication checks. Reports come in two types: aggregate (RUA) summaries and failure (RUF) per-incident detail.
How often are DMARC reports sent?
Aggregate reports are typically sent once every 24 hours by each participating mailbox provider. Failure reports, where supported, are sent closer to real time as individual failures occur.
What's the difference between RUA and RUF reports?
RUA (aggregate) reports summarize authentication results in bulk daily. RUF (failure) reports provide detail on individual failed messages as they happen.
How do I read a DMARC report?
Raw DMARC RUA reports are XML files, which aren't practical to read manually at any volume. A DMARC reporting service parses that XML and presents it as dashboards broken down by sending source, result, organization, host, and location so you can interpret it without technical parsing.
Is free DMARC reporting enough?
Free tools can work for a single domain with low mail volume and basic needs. As sending sources multiply and enforcement gets stricter, most teams need the deeper views like per-host detail, geolocation, historical trends, and alerting that free tiers typically don't include.
What should I do after reviewing a DMARC report?
Use the report to confirm every legitimate sending source is properly authenticated, investigate anything unrecognized, and fix any SPF or DKIM misalignment before moving your policy from monitoring to enforcement (p=quarantine or p=reject).

Visualize Your DMARC Reports in Minutes

Stop opening XML files. Get every view of your DMARC reporting – sources, results, organizations, hosts, geolocation, and countries in one dashboard.

Start 15-day trial Book a demo