DMARC aggregate (rua) reports explained: what those XML emails mean and what to do

What's happening: Once your DMARC record has a rua= address, Google, Microsoft, Yahoo and others email you a daily zipped XML file. Each row says which IP sent mail as your domain, how many messages, and whether SPF and DKIM passed and aligned. It's the safest way to find every service sending as you before moving DMARC to quarantine or reject.

How to fix it

  1. Unzip a report and look at each <record>: source_ip, count, and policy_evaluated (dkim / spf pass or fail).
  2. Identify each source IP (a reverse lookup usually shows Google, Microsoft, SendGrid, Mailchimp and so on). Rows from services you use that fail need DKIM set up for your domain in that service.
  3. Rows from IPs you don't recognise with large counts are usually spoofing: that's exactly what DMARC enforcement blocks.
  4. When every legitimate source passes for a couple of weeks, move p=none to p=quarantine, then p=reject.
  5. Too many reports in your inbox? Point rua= at a dedicated address, and if that address is on a different domain, that domain needs an authorization record.

Not sure which record is wrong? Check your domain free: it shows which of SPF, DKIM and DMARC is failing, in 5 seconds, no signup.

Other fix guides