Skip to main content
ESC
Start typing to search 370+ free tools

DMARC Report Analyzer

Upload the DMARC aggregate report your mailbox provider emailed you and get a readable summary — no XML reading required.

100% Free XML, .GZ & ZIP Supported Nothing Stored
Upload DMARC Report
Click to choose a file, or drag and drop Accepts .xml, .xml.gz, or .zip — the file exactly as your mailbox provider sent it
Secure by designYour uploaded report is processed instantly over an encrypted connection and never stored on our servers.
Encrypted in transitUploaded over HTTPS/TLS — nothing is sent in plain text.
Never storedThe report file and its contents are not saved to any database or log.
No third-party sharingYour report data is never shared with ads, trackers, or outside services.
Processed instantlyParsed on request and discarded immediately after the response.

About DMARC Report Analyzer

What Is a DMARC Report Analyzer?

DMARC-enabled domains receive periodic aggregate reports (in XML format) from receiving mail servers showing which sources sent mail claiming to be from your domain, and whether they passed authentication. These reports are hard to read manually — this tool parses them into a readable summary.

How to Use the DMARC Report Analyzer

  • Upload or paste your DMARC XML report
  • Click Analyze
  • Review the readable summary of sending sources and pass/fail results
  • Investigate any unexpected sending sources

Key Features

  • Converts raw XML into a readable summary
  • Highlights unauthorized or failing sources — a useful signal for spotting spoofing

Who Uses This Tool

Email administrators reviewing DMARC reports for unauthorized senders. Security teams monitoring for domain spoofing attempts.

Frequently Asked Questions

Where do I get DMARC reports?
They're sent automatically by receiving mail servers to the reporting email address specified in your DMARC DNS record.

Is this tool free?
Yes, analyzing DMARC reports is completely free.

Frequently Asked Questions

Where do I get a DMARC aggregate report?
Once your domain has a DMARC record with an rua= address, mailbox providers that receive mail claiming to be from your domain will email aggregate reports to that address, usually daily, as an XML attachment (often compressed as .gz or .zip).
Is my file uploaded or stored anywhere?
The file is parsed on request to generate your report and is not saved or retained afterward.
What does the "hostname" column mean?
It's the result of a reverse DNS lookup on the source IP, which often reveals which service actually sent the mail (e.g. a Google or Microsoft mail server) — useful for identifying unfamiliar senders.
What should I do about failing sources?
If a failing source is a legitimate service you use (like a marketing platform or CRM), add it to your SPF record or set up DKIM signing for it. If you don't recognize a source at all, it may be attempting to spoof your domain — this is exactly what DMARC reporting is designed to surface.
Why do the counts not match the number of emails I actually sent?
Aggregate reports only cover mail seen by that specific mailbox provider during the report's date range, not your total sending volume across every provider and every day.
Does this tool analyze forensic (ruf) reports too?
No, this analyzes aggregate (rua) reports, which use a standardized XML format. Forensic (ruf) reports use a different format and are rarely sent by mailbox providers today due to privacy concerns.

300+ Free SEO Tools — No Signup Needed

Keyword research, backlink checker, plagiarism detector, meta tags & more. All free, all instant.

Explore All Tools