DMARC aggregate (rua) reports explained: what those XML emails mean and what to do
What's happening: Once your DMARC record has a rua= address, Google, Microsoft, Yahoo and others email you a daily zipped XML file. Each row says which IP sent mail as your domain, how many messages, and whether SPF and DKIM passed and aligned. It's the safest way to find every service sending as you before moving DMARC to quarantine or reject.
How to fix it
- Unzip a report and look at each
<record>:source_ip,count, andpolicy_evaluated(dkim / spf pass or fail). - Identify each source IP (a reverse lookup usually shows Google, Microsoft, SendGrid, Mailchimp and so on). Rows from services you use that fail need DKIM set up for your domain in that service.
- Rows from IPs you don't recognise with large counts are usually spoofing: that's exactly what DMARC enforcement blocks.
- When every legitimate source passes for a couple of weeks, move
p=nonetop=quarantine, thenp=reject. - Too many reports in your inbox? Point
rua=at a dedicated address, and if that address is on a different domain, that domain needs an authorization record.
Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.
Other fix guides
- Gmail 550 5.7.26 "sender is unauthenticated"
- Outlook 550 5.7.515 "required authentication level"
- SPF permerror: too many DNS lookups
- Multiple SPF records found
- "dmarc=fail" in headers
- "dkim=none" / DKIM not set up
- Gmail "via" another domain next to your name
- "blocked using Spamhaus" bounce
- "spf=softfail" in headers
- Gmail 550 5.7.1 "likely unsolicited mail"
- Emails going to spam or junk (general)
- Yahoo / AOL 553 5.7.2 and DMARC rejections