Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DMARC aggregate reports are useful, but they were not written for people to read. They arrive as XML, usually compressed with GZIP and attached to an email. You do not need to read the raw file to get value from it. You need to pull out five things: which systems sent mail claiming your domain, how much mail each one sent, whether that mail aligned with SPF and DKIM, what the receiving server did with it, and whether any of it looks unauthorized.

What a DMARC aggregate report is

An aggregate report (often called a RUA report) is feedback that a receiving mail system sends to the address a domain owner publishes in the rua tag of its DMARC record. The report shows authentication outcomes, how the receiver applied the domain’s DMARC policy, and the volume of mail behind each outcome.

Two points follow from the standard. First, the rua tag decides where feedback goes. RFC 7489 requires receivers to support a mailto: reporting URI, and says they must not generate aggregate feedback when rua is absent. If your record has no rua tag, you will not receive these reports at all. Second, the report is not a list of spam messages. It is a summary of counts and outcomes grouped by sending source. Each receiver produces its own report, so the full picture only emerges when several reports are combined. (That last point is an interpretation of the aggregate design, not a separate rule in the standards.)

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: RFC 7489, RFC 9990.

Why the format is XML, GZIP, and email

RFC 7489 specifies that the aggregate report is carried as a MIME part in an email. Its Section 7.2.1.1 states: “The aggregate data MUST be an XML file that SHOULD be subjected to GZIP compression.” That sentence explains the format. The report is built to be parsed and combined by software, which is why it is structured data rather than a narrative. Filenames conventionally identify the reporting receiver, the policy domain, and the start and end times of the period covered. RFC 9990, the newer aggregate reporting specification, defines the filename pattern and requires an .xml or .xml.gz extension depending on whether the file is compressed.

#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

In practice, this means the attachment is a compressed file inside an email, and that file is an XML document. The email is only the delivery method. The meaning sits in the XML.

The fields that matter, and what each one answers

Most of the useful information sits in a few places in each report. The table below lists them in the order a reader should check them.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.
Element Question it answers What to look for first
Report metadata (reporting organization, report ID, date range) Which receiver sent this report, and for what period? Confirm the reporter and dates before reading any rows, so you do not mix periods or reporters.
Source IP and message count (one record per source) Which systems sent mail claiming your domain, and how much did each send? Sources you do not recognize, and any source with unusually high volume.
Disposition (policy-evaluated) What did the receiver do with the mail: none, quarantine, or reject? Any action that does not match the policy you have published.
Policy-evaluated SPF and DKIM Did each mechanism align with the domain in the From header? Failures on senders you know are yours.
Authentication results (raw SPF and DKIM outcomes and domains checked) What did the underlying SPF and DKIM checks find? The domains checked, which help explain a mismatch.

Microsoft’s DMARC field guide makes the same practical point: check whether each source IP is a legitimate sender or an unauthorized one, and treat high volume from an unknown IP as a possible spoofing signal. See Microsoft Learn: configure DMARC in Microsoft Defender for Office 365.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authentication passing is not the same as alignment

A message can pass SPF or DKIM and still fail DMARC. DMARC asks a narrower question: does the domain that passed authentication match the domain in the From header? That is what the policy-evaluated SPF and DKIM results record. The raw authentication results show whether SPF or DKIM passed at all, and which domains were checked.

Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

This distinction is the most common source of confusion in a report. A legitimate service can show a raw pass with a non-aligned domain, which then counts as a DMARC failure. Read the policy-evaluated values to answer “did this mail align?”, and read the raw results to find out why it did not.

How to read a report in five steps

  1. Confirm the reporter and time range. Check the report metadata for the reporting organization, report ID, and date range before you look at any counts.
  2. Group the rows by source IP, and sort by count. The highest-volume sources matter most. Note which ones you recognize as your own platforms.
  3. Check the disposition for each row. Compare the reported action with the policy you have published. An unexpected quarantine or reject on a legitimate sender is a finding in its own right.
  4. Check policy-evaluated SPF and DKIM for each row. A failure on a sender you control points to a configuration problem to fix. A failure on a sender you do not recognize points to an investigation.
  5. Use the raw authentication results to diagnose mismatches. Look at the domains checked. The mismatch usually shows which domain each mechanism authenticated.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do with an unfamiliar source

A failing row is a lead, not a verdict. Microsoft’s guidance is to validate unknown sources against your own sending services and mail flows before changing policy. The following framework gives a reasonable order of questions:

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
  • It matches a platform you use (email marketing, transactional mail, a helpdesk, a CRM, or a business app). The problem is probably configuration. Add the service to your SPF record, or set up DKIM signing with your domain, and check alignment.
  • It matches a forwarding path, such as a mailing list or a mail forwarder. SPF often fails when mail is forwarded because the forwarder sends from its own address. DKIM can still hold if the message was not altered. Check the DKIM result for that row.
  • It is unknown, low volume, and failing. Keep watching it over more reporting periods before deciding anything. A single row proves little.
  • It is unknown, high volume, and failing. Treat it as a possible spoofing attempt. Investigate with your mail team before you tighten the published policy, so that you do not block your own legitimate mail by mistake.

How often reports arrive

RFC 7489 says implementations MUST be able to send daily aggregate reports and SHOULD be able to send hourly reports when requested. Other reporting intervals are handled on a best-effort basis. This describes what receivers are required or encouraged to support. It does not promise that any particular receiver will send a report at a given hour, so expect a delay and gaps in the data.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Making reports readable without parsing XML by hand

Reading the raw XML is practical for a one-off check. For ongoing monitoring, many teams route the attachments into a DMARC report analyzer or aggregate-report monitoring service that parses the XML and shows source IPs, counts, and alignment results in a table. The standards do not rank these tools, and the sources cited here do not establish pricing or feature sets, so compare products on your own criteria:

  • Whether it accepts both compressed and uncompressed attachments and parses XML from many receivers.
  • Whether it shows source IP, count, disposition, and policy-evaluated SPF and DKIM side by side, so you can check alignment quickly.
  • Whether it keeps history across reporting periods, so one bad week does not look like a trend.
  • Whether it helps you separate authorized senders from possible spoofing, for example by letting you label known sources.
  • Whether it supports alerts for new, high-volume, or failing sources.

The reader question these tools answer is the one the standard already implies: which sources are sending mail as your domain, are your own senders passing, and is anything unauthorized getting through?

Standards and references

  • RFC 7489: the original DMARC specification, including the rua behavior, the XML and GZIP requirement, and reporting timing.
  • RFC 9990: the newer aggregate reporting specification, the one to check for current report structure and filenames.
  • Microsoft Learn: configure DMARC: operational guidance on interpreting source IPs and troubleshooting alignment.
  • DDMARC: DMARC aggregate reports: a vendor explainer. It is useful for common reader questions, but it is not a standard.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.